CVE-2016-9571: Remote Code Execution attacks
(updated )
This package is vulnerable to Java object de-serialization vulnerability. Camel allows to specify such a type through the CamelJacksonUnmarshalType
property. De-serializing untrusted data can lead to security flaws as demonstrated in various similar reports about Java de-serialization issues.
References
Detect and mitigate CVE-2016-9571 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →