QID 982978
QID 982978: Java (maven) Security Update for org.apache.camel:camel-core (GHSA-h896-mx9x-g32g)
Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-h896-mx9x-g32g for updates pertaining to this vulnerability.
Vendor References
- GHSA-h896-mx9x-g32g -
github.com/advisories/GHSA-h896-mx9x-g32g
CVEs related to QID 982978
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-h896-mx9x-g32g | org.apache.camel:camel-core |
|