QID 981371
QID 981371: Java (maven) Security Update for org.apache.camel:camel-core (GHSA-3hrc-f439-727g)
XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attackers to read arbitrary files via an external entity in an SAXSource.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-3hrc-f439-727g for updates pertaining to this vulnerability.
Vendor References
- GHSA-3hrc-f439-727g -
github.com/advisories/GHSA-3hrc-f439-727g
CVEs related to QID 981371
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3hrc-f439-727g | org.apache.camel:camel-core |
|