Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: apache

Published: 2020-05-14T16:26:03

Updated: 2021-01-20T14:42:05

Reserved: 2020-04-21T00:00:00


Link: CVE-2020-11972

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-05-14T17:15:12.117

Modified: 2021-03-15T22:15:10.093


Link: CVE-2020-11972

JSON object: View

cve-icon Redhat Information

No data.

CWE