GHSA-5whj-523x-6j68
GitHub Security Advisory
Apache Camel camel-hessian component vulnerable to Java object deserialization
✓ GitHub Reviewed
CRITICAL
Has CVE
Advisory Details
The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.
Affected Packages
Maven
org.apache.camel:camel-hessian
Affected versions:
2.0
(fixed in 2.19.4)
Maven
org.apache.camel:camel-hessian
Affected versions:
2.20.0
(fixed in 2.20.1)
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: July 27, 2025 6:35 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.