org.apache.camel:camel-core@2.14.0 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the org.apache.camel:camel-core package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
XML External Entity (XXE) Injection

org.apache.camel:camel-core is a versatile open-source integration framework based on known Enterprise Integration Patterns.

XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attackers to read arbitrary files via an external entity in an SAXSource.

[,2.13.3] [2.14.0,2.14.1]
  • M
XML External Entity (XXE) Injection

org.apache.camel:camel-core is a versatile open-source integration framework based on known Enterprise Integration Patterns.

Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an invalid XML (1) String or (2) GenericFile object in an XPath query.

[,2.13.3] [2.14.0,2.14.1]