Red Hat Bugzilla – Bug 1513376
CVE-2017-12634 camel-castor: Apache Camel's Castor unmarshalling operation is vulnerable to Remote Code Execution attacks
Last modified: 2018-05-10 14:23:16 EDT
Apache Camel's camel-castor component is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws. Versions Affected: Camel 2.19.0 to 2.19.3 and Camel 2.20.0 The unsupported Camel 2.x (2.18 and earlier) versions may be also affected. References: https://camel.apache.org/security-advisories.data/CVE-2017-12634.txt.asc https://issues.apache.org/jira/browse/CAMEL-11929
Fuse will track this effort with [1]. GSS Product liaison Susan Javurek has been added to the cc:list. [1] https://issues.jboss.org/browse/ENTESB-7452
This issue has been addressed in the following products: Red Hat JBoss Fuse Via RHSA-2018:0319 https://access.redhat.com/errata/RHSA-2018:0319