CVE-2020-11972
Deserialization of Untrusted Data in Apache Camel RabbitMQ
9.8
CRITICAL
CVSS 3.1
EPSS 5.5%
Description
Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.
How to fix CVE-2020-11972
To remediate CVE-2020-11972, upgrade the affected package to a fixed version below.
- Maven/org.apache.camel:camel-rabbitmq—upgrade to 2.25.1 or later
Is CVE-2020-11972 being exploited?
Moderate — EPSS is 5.5%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 2.25.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |