QID 981423
QID 981423: Java (maven) Security Update for org.apache.camel:camel-core (GHSA-2fw5-rvf2-jq56)
The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other unspecified impact via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-2fw5-rvf2-jq56 for updates pertaining to this vulnerability.
Vendor References
- GHSA-2fw5-rvf2-jq56 -
github.com/advisories/GHSA-2fw5-rvf2-jq56
CVEs related to QID 981423
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2fw5-rvf2-jq56 | org.apache.camel:camel-core |
|