Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2020-11972

Apache Camel RabbitMQ enables Java deserialization by default.

Technology

Apache Camel

CVSS Score

9.8 / 10.0

Affected Versions

>=2.22.0 <=2.25.0; >=3.0.0 <=3.1.0

Upstream Fix

See upstream advisory

Published

May 14, 2020

OSSeva Coverage

Fixed upstream

Description

Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.

Is your Apache Camel deployment affected?

If you're running >=2.22.0 <=2.25.0; >=3.0.0 <=3.1.0, you need this patch. Book a discovery call to get covered.