You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@activemq.apache.org by "Aman Mishra (Jira)" <ji...@apache.org> on 2021/07/15 11:32:00 UTC
[jira] [Created] (AMQ-8319) Vulnerable Camel-Core Version (2.25.2)
Needs to be upgraded
Aman Mishra created AMQ-8319:
--------------------------------
Summary: Vulnerable Camel-Core Version (2.25.2) Needs to be upgraded
Key: AMQ-8319
URL: https://issues.apache.org/jira/browse/AMQ-8319
Project: ActiveMQ
Issue Type: Bug
Reporter: Aman Mishra
We are using activemq-all latest version i.e. 5.16.2. It internally uses camel-core version 2.25.2, which shows vulnerable in our aqua scan. It has been recommended to upgrade this camel-core to at least 3.2.0 version.
[7.5] [CVE-2020-11971] [camel-core] [2.25.2] [remedy_platform/remedy/ars]
[7.3] [CVE-2019-10086] [commons-beanutils] [1.8.0] [remedy_platform/remedy/ars]
*Aqua Description :* Apache Camel's JMX is vulnerable to Rebind Flaw. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.x, 3.0.0 up to 3.1.0 is affected. Users should upgrade to 3.2.0.
*Vendor Statement :*
*Vendor URL :*
*NVD URL :* [https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-11971]
*Fix Version :* 3.2.0
*Solution :* Upgrade package camel-core to version 3.2.0 or above.
*Classification :*
*Publish Date :* 2020-05-14
*Modification Date :* 2021-02-18
*First Found Date :* 2021-05-22
*Aqua Vectors :* CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
*Aqua Scoring System :* CVSS V3
*CVE Id :* CVE-2020-11971
*Type :* package
*Format :* java
*Path :*
*Resource Name :* camel-core
*version :* 2.25.2
*Arch :*
*CPE :* pkg:/java:*:org.apache.camel#camel-core:2.25.2
*OS :* centos
*OS Version :* 7
--
This message was sent by Atlassian Jira
(v8.3.4#803005)