Apache Camel's camel-xstream component is vulnerable to Java object
de-serialisation vulnerability.
Such as de-serializing untrusted data can lead to security flaws as
demonstrated in various similar reports about Java de-serialization
issues.
Please study this security vulnerability carefully!
CVE-2015-5344 - [1]
You can download the fixed Apache Camel 2.15.x and 2.16.x version from
the Apache mirrors [2] or from the Central Maven repository.
[1] http://camel.apache.org/
[2] http://camel.apache.org/
On behalf of the Camel PMC,
Claus Ibsen
Komentarų nėra:
Rašyti komentarą