QID 982978

QID 982978: Java (maven) Security Update for org.apache.camel:camel-core (GHSA-h896-mx9x-g32g)

Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-h896-mx9x-g32g for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982978

    Software Advisories
    Advisory ID Software Component Link
    GHSA-h896-mx9x-g32g org.apache.camel:camel-core URL Logo github.com/advisories/GHSA-h896-mx9x-g32g