Apache Camel security advisory: CVE-2020-11971

Severity

MEDIUM

Summary

Apache Camel JMX Rebind Flaw Vulnerability

Versions affected

2.22.x, 2.23.x, 2.24.x, 2.25.x, 3.0.0 up to 3.1.0

Versions fixed

3.2.0

Description

Apache Camel JMX Rebind Flaw Vulnerability

Notes

The JIRA ticket: https://issues.apache.org/jira/browse/CAMEL-14811 refers to the various commits that resovoled the issue, and have more details.

Mitigation

Users should upgrade to 3.2.0

Credit

This issue was discovered by Colm O. HEigeartaigh <coheigea at apache dot org> from Apache Software Foundation and Jonathan Gallimore <jonathan dot gallimore at gmail dot com> from Tomitribe

References

PGP signed advisory data: CVE-2020-11971.txt.asc
Mitre CVE Entry: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11971