CVE-2020-11973: Critical severity Apache Camel vulnerability
A flaw was found in camel. Apache Camel RabbitMQ enables java deserialization, by default, without any means of disabling which can lead to arbitrary code being executed. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-11973?
CVE-2020-11973 is a vulnerability in Apache Camel that allows arbitrary code execution through Java deserialization.
What is the severity of CVE-2020-11973?
The severity of CVE-2020-11973 is critical, with a severity value of 9.8.
How does CVE-2020-11973 affect data confidentiality and integrity?
CVE-2020-11973 can lead to a compromise of data confidentiality and integrity.
Which versions of Apache Camel are affected by CVE-2020-11973?
Versions 2.22.x, 2.23.x, 2.24.x, and 2.25.0 of Apache Camel are affected by CVE-2020-11973.
How can I fix CVE-2020-11973?
To fix CVE-2020-11973, upgrade to Apache Camel version 3.2.0 or higher.