原始 OSV JSON{
"id": "GHSA-h79p-32mx-fjj9",
"aliases": [
"CVE-2020-11973"
],
"details": "Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.",
"summary": "Apache Camel Netty enables Java deserialization by default",
"affected": [
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.0.0"
},
{
"fixed": "3.2.0"
}
]
}
],
"package": {
"name": "org.apache.camel:camel-netty",
"ecosystem": "Maven"
}
}
],
"modified": "2022-10-06T18:15:00Z",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"published": "2020-05-21T21:09:04Z",
"references": [
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-11973",
"type": "ADVISORY"
},
{
"url": "https://camel.apache.org/security/CVE-2020-11973.html",
"type": "WEB"
},
{
"url": "https://github.com/apache/camel",
"type": "PACKAGE"
},
{
"url": "https://www.oracle.com//security-alerts/cpujul2021.html",
"type": "WEB"
},
{
"url": "https://www.oracle.com/security-alerts/cpuApr2021.html",
"type": "WEB"
},
{
"url": "https://www.oracle.com/security-alerts/cpujan2021.html",
"type": "WEB"
},
{
"url": "https://www.oracle.com/security-alerts/cpuoct2020.html",
"type": "WEB"
},
{
"url": "http://www.openwall.com/lists/oss-security/2020/05/14/9",
"type": "WEB"
}
],
"schema_version": "1.4.0",
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": "CRITICAL",
"github_reviewed": true,
"nvd_published_at": "2020-05-14T17:15:00Z",
"github_reviewed_at": "2020-05-21T17:42:21Z"
}
}