Deserialization of Untrusted Data in Apache Camel CassandraQL

説明

Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserialization. Under specific conditions it is possible to deserialize malicious payload.This issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 before 4.0.4, from 4.1.0 before 4.4.0.

Users are recommended to upgrade to version 4.4.0, which fixes the issue. If users are on the 4.0.x LTS releases stream, then they are suggested to upgrade to 4.0.4. If users are on 3.x, they are suggested to move to 3.21.4 or 3.22.1

基本情報

タイプ
reviewed
深刻度
high
GitHub 上のアドバイザリ
アドバイザリを開く ↗
リポジトリのアドバイザリ
ソースコード
ソースを見る ↗
公開(アドバイザリ)
2024-02-20 15:31:06 UTC
更新
2026-03-22 05:07:50 UTC
GitHub レビュー済み
2024-02-21 00:22:04 UTC
NVD で公開
2024-02-20

EPSS Score

Score Percentile
1.03% 77.16%

CVSS Scores

No CVSS scores in this advisory.

Identifiers

CWEs

CWE id Name
CWE-502 Deserialization of Untrusted Data

Credits

  • oscerd (analyst)

Affected packages (4)

Vulnerable version ranges and first patched releases as published by GitHub.

Ecosystem Package Vulnerable range First patched Vulnerable functions
maven org.apache.camel:camel-cassandraql >= 3.0.0, < 3.21.4 3.21.4
maven org.apache.camel:camel-cassandraql >= 3.22.0, < 3.22.1 3.22.1
maven org.apache.camel:camel-cassandraql >= 4.0.0, < 4.0.4 4.0.4
maven org.apache.camel:camel-cassandraql >= 4.1.0, < 4.4.0 4.4.0

References

cvelogic Threat Intelligence