CVE-2017-12633
The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
- Affected products
- Apache Camel
- Apache Camel
- < 2.19.4, 2.20.1
- CVSS 3.0
- 9.8 CRITICAL
- EPSS
- 7.1% (94th percentile)
- Weakness
- CWE-502
- NVD status
- Modified
- Published
- 2017-11-15
CVE-2017-12633 at NVD
3 known exploits for CVE-2017-12633
Proof-of-concept code and exploit modules indexed by Sploitus