VDB

CVE-2017-3159

CVE-2017-3159 PUBLISHED CVSS 7.5 HIGH

Reported by apache · Published March 7, 2017

Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to security flaws.

Risk Scores

CVSS 2.0
7.5

Affected Products

VendorProductVersions
Apache Software FoundationApache Camel2.17.0 to 2.17.4, 2.18.0 to 2.18.1, The unsupported Camel 2.x (2.14 and earlier) versions may be also affected.
Mavenorg.apache.camel:camel-snakeyaml0, 0
Apache Software FoundationApache Camel*, 2.18.0 to 2.18.1, The unsupported Camel 2.x (2.14 and earlier) versions may be also affected.

Timeline

  • Mar 7, 2017 CVE Published
  • May 24, 2019 CVE Updated
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 25, 2021 EPSS Score
  • Dec 29, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 2, 2022 EPSS Score
  • May 4, 2022 EPSS Score
  • Sep 7, 2022 EPSS Score
  • Nov 9, 2022 EPSS Score
  • Jan 11, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›