Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.apache.camel:camel-jetty(Maven) | 0 | 2.15.5 | N/A |
| org.apache.camel:camel-jetty(Maven) | 2.16.0 | 2.16.1 | N/A |
| org.apache.camel:camel-servlet(Maven) | 0 | 2.15.5 | N/A |
| org.apache.camel:camel-servlet(Maven) | 2.16.0 | 2.16.1 | N/A |
| org.apache.camel:camel-http(Maven) | 0 | 2.15.5 | N/A |
| org.apache.camel:camel-http(Maven) | 2.16.0 | 2.16.1 | N/A |
| org.apache.camel:camel-http-common(Maven) | 0 | 2.15.5 | N/A |
| org.apache.camel:camel-http-common(Maven) | 2.16.0 | 2.16.1 | N/A |
| org.apache.camel:camel-http4(Maven) | 0 | 2.15.5 | N/A |
| org.apache.camel:camel-http4(Maven) | 2.16.0 | 2.16.1 | N/A |
| org.apache.camel:camel-ahc(Maven) | 0 | 2.15.5 | N/A |
| org.apache.camel:camel-ahc(Maven) | 2.16.0 | 2.16.1 | N/A |
CVSS Metrics