REDHAT-BUG-1049675: Medium severity red hat build of apache camel vulnerability
It was found that the Apache Camel XSLT component would resolve entities in XML messages when transforming them using an xslt: route. A remote attacker able to submit messages to an xslt: Camel route could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1049675?
The severity of REDHAT-BUG-1049675 is high due to potential information disclosure risks.
How do I fix REDHAT-BUG-1049675?
To fix REDHAT-BUG-1049675, update to the latest version of the Apache Camel that addresses this vulnerability.
What does REDHAT-BUG-1049675 affect?
REDHAT-BUG-1049675 affects the Apache Camel XSLT component used in XML message processing.
Can REDHAT-BUG-1049675 lead to a remote code execution?
REDHAT-BUG-1049675 does not directly lead to remote code execution but allows unauthorized file access.
Who is affected by REDHAT-BUG-1049675?
Any users running the Red Hat Build of Apache Camel with the XSLT component enabled are affected by REDHAT-BUG-1049675.