First published: Wed Jan 08 2014(Updated: )
It was found that the Apache Camel XSLT component would resolve entities in XML messages when transforming them using an xslt: route. A remote attacker able to submit messages to an xslt: Camel route could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Camel | <=2.11.3 | |
Apache Camel | =1.0.0 | |
Apache Camel | =1.1.0 | |
Apache Camel | =1.2.0 | |
Apache Camel | =1.3.0 | |
Apache Camel | =1.4.0 | |
Apache Camel | =1.5.0 | |
Apache Camel | =1.6.0 | |
Apache Camel | =1.6.1 | |
Apache Camel | =1.6.2 | |
Apache Camel | =1.6.3 | |
Apache Camel | =1.6.4 | |
Apache Camel | =2.0.0 | |
Apache Camel | =2.0.0-milestone1 | |
Apache Camel | =2.0.0-milestone2 | |
Apache Camel | =2.0.0-milestone3 | |
Apache Camel | =2.1.0 | |
Apache Camel | =2.10.0 | |
Apache Camel | =2.10.1 | |
Apache Camel | =2.10.2 | |
Apache Camel | =2.10.3 | |
Apache Camel | =2.10.4 | |
Apache Camel | =2.10.5 | |
Apache Camel | =2.10.6 | |
Apache Camel | =2.10.7 | |
Apache Camel | =2.11.0 | |
Apache Camel | =2.11.1 | |
Apache Camel | =2.11.2 | |
Apache Camel | =2.12.0 | |
Apache Camel | =2.12.1 | |
Apache Camel | =2.12.2 | |
maven/org.apache.camel:camel-core | >=2.12.0<2.12.3 | 2.12.3 |
maven/org.apache.camel:camel-core | <2.11.4 | 2.11.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.