Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2017-3159
Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization…
Technology
Apache Camel
CVSS Score
9.8 / 10.0
Affected Versions
<=2.14.4; >=2.17.0 <=2.17.4; >=2.18.0 <=2.18.1
Upstream Fix
See upstream advisory
Published
March 7, 2017
OSSeva Coverage
Fixed upstream
Description
Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to security flaws.
Is your Apache Camel deployment affected?
If you're running <=2.14.4; >=2.17.0 <=2.17.4; >=2.18.0 <=2.18.1, you need this patch. Book a discovery call to get covered.