CVE-2017-5643: SSRF

Published Mar 16, 2017
·
Updated

Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.

Other sources

Description: The Validation Component of Apache Camel evaluates DTD headers of XML stream sources, although a validation against XML schemas (XSD) is executed. Remote attackers can use this feature to make Server-Side Request Forgery (SSRF) attacks by sending XML documents with remote DTDs URLs or XML External Entities (XXE). The vulnerability is not given for SAX or StAX sources.

Mitigation: 2.17.x users should upgrade to 2.17.6, 2.18.x users should upgrade to 2.18.3.

The JIRA tickets https://issues.apache.org/jira/browse/CAMEL-10894 refers to the various commits that resolved the issue, and have more details.

The Validation Component of Apache Camel evaluates DTD headers of XML stream sources, although a validation against XML schemas (XSD) is executed. Remote attackers can use this feature to make Server-Side Request Forgery (SSRF) attacks by sending XML documents with remote DTDs URLs or XML External Entities (XXE). The vulnerability is not given for SAX or StAX sources.

Versions Affected: Camel 2.17.0 to 2.17.5, Camel 2.18.0 to 2.18.2 The unsupported Camel 2.x (2.16 and earlier) versions may be also affected.

External Reference:

https://camel.apache.org/security-advisories.data/CVE-2017-5643.txt

Red Hat

Affected Software

14 affected componentsFixes available
maven/org.apache.camel:camel-core>=2.18.0<2.18.2
2.18.2
maven/org.apache.camel:camel-core<2.17.6
2.17.6
redhat/camel-core<2.17.6
2.17.6
redhat/camel-core<2.18.3
2.18.3
Apache Camel<=2.16.0
Apache Camel=2.17.0
Apache Camel=2.17.1
Apache Camel=2.17.2
Apache Camel=2.17.3
Apache Camel=2.17.4
Apache Camel=2.17.5
Apache Camel=2.18.0
Apache Camel=2.18.1
Apache Camel=2.18.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade maven/org.apache.camel:camel-core to a version that resolves this vulnerability.

    Fixed in 2.18.2
  2. Upgrade

    Upgrade maven/org.apache.camel:camel-core to a version that resolves this vulnerability.

    Fixed in 2.17.6
  3. Upgrade

    Upgrade redhat/camel-core to a version that resolves this vulnerability.

    Fixed in 2.17.6
  4. Upgrade

    Upgrade redhat/camel-core to a version that resolves this vulnerability.

    Fixed in 2.18.3
  5. Upgrade

    Upgrade apache/camel to a version that resolves this vulnerability.

    Fixed in 2.17.6
  6. Upgrade

    Upgrade apache/camel to a version that resolves this vulnerability.

    Fixed in 2.18.3

Event History

Mar 16, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Data Sourced
via NVD·03:59 PM
DescriptionSeverityWeaknessAffected Software
Oct 16, 2018
Advisory Published
11:13 PM

Frequently Asked Questions

1

What is the severity of CVE-2017-5643?

CVE-2017-5643 has a moderate severity level due to its potential exploitation via Server-Side Request Forgery (SSRF) using remote DTDs and XML External Entity (XXE).

2

How do I fix CVE-2017-5643?

To fix CVE-2017-5643, upgrade Apache Camel to version 2.18.2 or 2.17.6 or later.

3

Which versions are affected by CVE-2017-5643?

CVE-2017-5643 affects various versions of Apache Camel, specifically versions prior to 2.17.6 and 2.18.2.

4

What kind of attacks can exploit CVE-2017-5643?

CVE-2017-5643 allows attackers to exploit SSRF vulnerabilities through remote DTDs and perform XXE attacks.

5

Is there a specific version of Apache Camel that is a safe upgrade for CVE-2017-5643?

Yes, upgrading to Apache Camel version 2.18.2 or 2.17.6 or their later versions mitigates the risk associated with CVE-2017-5643.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203