CVE-2020-11973
Apache Camel Netty enables Java deserialization by default
9.8
CRITICAL
CVSS 3.1
EPSS 6.6%
Description
Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.
How to fix CVE-2020-11973
To remediate CVE-2020-11973, upgrade the affected package to a fixed version below.
- Maven/org.apache.camel:camel-netty—upgrade to 3.2.0 or later
Is CVE-2020-11973 being exploited?
Moderate — EPSS is 6.6%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- >= 3.0.0, < 3.2.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |