Lucene search

K
osvGoogleOSV:CVE-2020-11972
HistoryMay 14, 2020 - 5:15 p.m.

CVE-2020-11972

2020-05-1417:15:12
Google
osv.dev
9

6.7 Medium

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

81.7%

Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.

CPENameOperatorVersion
cameleqcamel-3.1.0
cameleqcamel-3.0.0

6.7 Medium

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

81.7%