CVE-2015-5344: Critical severity red hat build of apache camel vulnerability
Published Feb 3, 2016
·Updated
The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.
Affected Software
4 affected componentsFixes available
maven/org.apache.camel:camel-xstream=2.16.0
2.16.1
maven/org.apache.camel:camel-xstream<2.15.5
2.15.5
Apache Camel<=2.15.4
Apache Camel=2.16.0
Event History
Feb 3, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Oct 16, 2018
Advisory Published
11:10 PM
Frequently Asked Questions
1
What is the severity of CVE-2015-5344?
CVE-2015-5344 has a high severity rating, indicating significant risk due to remote command execution vulnerabilities.
2
How do I fix CVE-2015-5344?
To fix CVE-2015-5344, upgrade to Apache Camel version 2.15.5 or 2.16.1 or later.
3
What is the impact of CVE-2015-5344?
The impact of CVE-2015-5344 allows remote attackers to execute arbitrary commands on the affected systems.
4
Which versions of Apache Camel are affected by CVE-2015-5344?
Apache Camel versions prior to 2.15.5 and 2.16.0 are affected by CVE-2015-5344.
5
Is the camel-xstream component in Apache Camel vulnerable in versions 2.16.1 and above?
No, the camel-xstream component is not vulnerable in Apache Camel versions 2.16.1 and above.