CVE

CVE-2016-9571

CVE-2016-9571

Apache Camel’s camel-jackson and camel-jacksonxml components are vulnerable to Java object de-serialization vulnerability. Camel allows to specify such a type through the ‘CamelJacksonUnmarshalType’ property. De-serializing untrusted data can lead to security flaws as demonstrated in various similar reports about Java de-serialization issues.

Source: CVE-2016-9571

Exit mobile version