

Apache Camel’s camel-jackson and camel-jacksonxml components are vulnerable to Java object de-serialization vulnerability. Camel allows to specify such a type through the ‘CamelJacksonUnmarshalType’ property. De-serializing untrusted data can lead to security flaws as demonstrated in various similar reports about Java de-serialization issues.

Source: CVE-2016-9571

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다