Camel-xstream component in Apache Camel can allow remote attackers to execute arbitrary commands
Critical severity
GitHub Reviewed
Published
Oct 16, 2018
to the GitHub Advisory Database
•
Updated Dec 19, 2023
Package
Affected versions
< 2.15.5
= 2.16.0
Patched versions
2.15.5
2.16.1
Description
Published to the GitHub Advisory Database
Oct 16, 2018
Reviewed
Jun 16, 2020
Last updated
Dec 19, 2023
The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.
References