Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2018-8027

Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.

Technology

Apache Camel

CVSS Score

9.8 / 10.0

Affected Versions

>=2.20.0 <=2.20.3; 2.21.0

Upstream Fix

See upstream advisory

Published

July 31, 2018

OSSeva Coverage

Fixed upstream

Description

Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.

Is your Apache Camel deployment affected?

If you're running >=2.20.0 <=2.20.3; 2.21.0, you need this patch. Book a discovery call to get covered.