VYPR
Critical severity9.8NVD Advisory· Published Mar 7, 2017· Updated May 13, 2026

CVE-2017-3159

CVE-2017-3159

Description

Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to security flaws.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.camel:camel-snakeyamlMaven
< 2.17.52.17.5
org.apache.camel:camel-snakeyamlMaven
>= 2.18.0, < 2.18.22.18.2

Affected products

2
  • cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:*
    Range: <=2.14.4
  • Apache Software Foundation/Apache Camelv5
    Range: 2.17.0 to 2.17.4

Patches

7

Vulnerability mechanics

Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

19

News mentions

0

No linked articles in our index yet.