Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to security flaws.
2017-03-07T15:59:00.517
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | camel | ≤ 2.14.4 | Yes |
Application | apache | camel | ≤ 2.17.4 | Yes |
Application | apache | camel | ≤ 2.18.1 | Yes |