{"id":"CVE-2017-12633","details":"The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.","aliases":["GHSA-5whj-523x-6j68"],"modified":"2026-07-08T10:54:34.191565Z","published":"2017-11-15T15:29:00.210Z","references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3E"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/101874"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:0319"},{"type":"REPORT","url":"http://camel.apache.org/security-advisories.data/CVE-2017-12633.txt.asc"},{"type":"REPORT","url":"https://issues.apache.org/jira/browse/CAMEL-11923"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/camel","events":[{"introduced":"6c88ad61b73dbfbc49c62624096ca0c250111430"},{"fixed":"4e2d4a1a011af53ee249ecb59906117c15bc5528"},{"introduced":"aff4434eb839e9d690a0419230264b14a0ddeb22"},{"fixed":"1398cc8e8f58b2bf5c9e9a7f8dffd113ae290d88"}],"database_specific":{"extracted_events":[{"introduced":"2.0.0"},{"fixed":"2.19.4"},{"introduced":"2.20.0"},{"fixed":"2.20.1"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:*"}}],"versions":["camel-2.20.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-12633.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}