Vulnerability Description
Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to security flaws.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Camel | <= 2.14.4 |
Related Weaknesses (CWE)
References
- http://camel.apache.org/security-advisories.data/CVE-2017-3159.txt.asc?version=1Vendor Advisory
- http://www.openwall.com/lists/oss-security/2017/05/22/2Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/96321Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:0868Third Party Advisory
- https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0
- https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e6
- https://www.github.com/mbechler/marshalsec/blob/master/marshalsec.pdf?raw=trueThird Party Advisory
- http://camel.apache.org/security-advisories.data/CVE-2017-3159.txt.asc?version=1Vendor Advisory
- http://www.openwall.com/lists/oss-security/2017/05/22/2Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/96321Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:0868Third Party Advisory
- https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0
- https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e6
- https://www.github.com/mbechler/marshalsec/blob/master/marshalsec.pdf?raw=trueThird Party Advisory
FAQ
What is CVE-2017-3159?
CVE-2017-3159 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to security flaws.
How severe is CVE-2017-3159?
CVE-2017-3159 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-3159?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Camel.