First published: Tue May 28 2019(Updated: )
Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Camel | <2.24.0 | |
Oracle Enterprise Data Quality | =11.1.1.9.0 | |
Oracle Enterprise Manager Base Platform | =13.3.0.0 | |
Oracle Enterprise Manager Base Platform | =13.4.0.0 | |
Oracle FLEXCUBE Private Banking | =12.0.0 | |
Oracle FLEXCUBE Private Banking | =12.1.0 | |
Oracle Enterprise Repository | =12.1.3.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0188 is a vulnerability in Apache Camel prior to version 2.24.0 that allows XML external entity injection (XXE) attacks.
CWE-611 is the Common Weakness Enumeration identifier for XML External Entity (XXE) Injection vulnerabilities.
CVE-2019-0188 affects Apache Camel by allowing an attacker to perform XXE attacks due to the usage of an outdated and vulnerable JSON-lib library.
CVE-2019-0188 has a severity level of high, with a CVSS score of 7.5.
To fix CVE-2019-0188, upgrade to Apache Camel version 2.24.0 or newer, which removes the vulnerable camel-xmljson component.