org.apache.camel:camel-jetty9@2.15.2 vulnerabilities

Camel Jetty9 support

Direct Vulnerabilities

Known vulnerabilities in the org.apache.camel:camel-jetty9 package. This does not include vulnerabilities belonging to this package’s dependencies.

Vulnerability Vulnerable Version
Arbitrary Command Execution

org.apache.camel:camel-jetty9 is a versatile open-source integration framework based on known Enterprise Integration Patterns.

Affected versions of this package are vulnerable to Arbitrary Command Execution. It allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.

How to fix Arbitrary Command Execution?

Upgrade org.apache.camel:camel-jetty9 to version 2.15.5, 2.16.1 or higher.

[2.15.0,2.15.5) [2.16.0,2.16.1)