VYPR
Critical severity9.8NVD Advisory· Published Nov 15, 2017· Updated May 13, 2026

CVE-2017-12633

CVE-2017-12633

Description

The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.camel:camel-hessianMaven
>= 2.0, < 2.19.42.19.4
org.apache.camel:camel-hessianMaven
>= 2.20.0, < 2.20.12.20.1

Affected products

2
  • cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:*
    Range: >=2.0.0,<2.19.4
  • Apache Software Foundation/Apache Camelv5
    Range: 2.19.0 to 2.19.3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

10

News mentions

0

No linked articles in our index yet.