Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2015-5344

camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote…

Technology

Apache Camel

CVSS Score

9.8 / 10.0

Affected Versions

<=2.15.4; 2.16.0

Upstream Fix

See upstream advisory

Published

February 3, 2016

OSSeva Coverage

Fixed upstream

Description

The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.

Is your Apache Camel deployment affected?

If you're running <=2.15.4; 2.16.0, you need this patch. Book a discovery call to get covered.