Red Hat Bugzilla – Bug 1513382
CVE-2017-12633 camel-hessian: Apache Camel's Hessian unmarshalling operation is vulnerable to Remote Code Execution attacks
Last modified: 2018-02-15 13:26:28 EST
Apache Camel's camel-hessian component is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws. Versions Affected: Camel 2.19.0 to 2.19.3 and Camel 2.20.0 The unsupported Camel 2.x (2.18 and earlier) versions may be also affected. References: https://camel.apache.org/security-advisories.data/CVE-2017-12633.txt.asc https://issues.apache.org/jira/browse/CAMEL-11923
This issue has been addressed in the following products: Red Hat JBoss Fuse Via RHSA-2018:0319 https://access.redhat.com/errata/RHSA-2018:0319