Apache Camel's camel-castor component is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
Versions Affected: Camel 2.19.0 to 2.19.3 and Camel 2.20.0 The unsupported Camel 2.x (2.18 and earlier) versions may be also affected.
References:
https://camel.apache.org/security-advisories.data/CVE-2017-12634.txt.asc https://issues.apache.org/jira/browse/CAMEL-11929
Apache Camel's camel-hessian component is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
Versions Affected: Camel 2.19.0 to 2.19.3 and Camel 2.20.0 The unsupported Camel 2.x (2.18 and earlier) versions may be also affected.
References:
https://camel.apache.org/security-advisories.data/CVE-2017-12633.txt.asc https://issues.apache.org/jira/browse/CAMEL-11923