Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2017-3159

Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization…

Technology

Apache Camel

CVSS Score

9.8 / 10.0

Affected Versions

<=2.14.4; >=2.17.0 <=2.17.4; >=2.18.0 <=2.18.1

Upstream Fix

See upstream advisory

Published

March 7, 2017

OSSeva Coverage

Fixed upstream

Description

Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to security flaws.

Is your Apache Camel deployment affected?

If you're running <=2.14.4; >=2.17.0 <=2.17.4; >=2.18.0 <=2.18.1, you need this patch. Book a discovery call to get covered.