CVE-2017-3159 PUBLISHED

Reported by apache · Published March 7, 2017

Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to security flaws.

Affected Products

VendorProductVersions
Apache Software FoundationApache Camel2.17.0 to 2.17.4, 2.18.0 to 2.18.1, The unsupported Camel 2.x (2.14 and earlier) versions may be also affected.
Mavenorg.apache.camel:camel-snakeyaml0, 0
Apache Software FoundationApache Camel2.17.0 to 2.17.4, 2.18.0 to 2.18.1, The unsupported Camel 2.x (2.14 and earlier) versions may be also affected.

Timeline

References

Open in Interactive Console →