First published: Wed Jun 03 2015(Updated: )
Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an invalid XML (1) String or (2) GenericFile object in an XPath query.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Camel | <=2.13.3 | |
Apache Camel | =2.14.0 | |
Apache Camel | =2.14.1 | |
maven/org.apache.camel:camel-core | >=2.14.0<2.14.2 | 2.14.2 |
maven/org.apache.camel:camel-core | <2.13.4 | 2.13.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.