CVE-2017-5643
published 2017-03-16CVE-2017-5643: Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.
PriorityP339high7.4CVSS 3.0
AVNACLPRNUIRSCCNIHAN
EPSS
4.89%
91.2th percentile
Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | camel | <= 2.16.0 | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache_software_foundation | apache_camel | — | — |
| apache_software_foundation | apache_camel | — | — |
| apache_software_foundation | apache_camel | — | — |
CVSS provenance
nvdv3.07.4HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_apache7.4MEDIUM
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.
osv·2018-10-16
CVE-2017-5643 [HIGH] Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.
Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.
Description: The Validation Component of Apache Camel evaluates DTD headers of XML stream sources, although a validation against XML schemas (XSD) is executed. Remote attackers can use this feature to make Server-Side Request Forgery (SSRF) attacks by sending XML documents with remote DTDs URLs or XML External Entities (XXE). The vulnerability is not given for SAX or StAX sources.
Mitigation: 2.17.x users should upgrade to 2.17.6, 2.18.x users should upgrade to 2.18.3.
The JIRA tickets https://issues.apache.org/jira/browse/CAMEL-10894 refers to the various commits that resolved the issue, and have more details.
GHSA
Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.
ghsa·2018-10-16
CVE-2017-5643 [HIGH] CWE-918 Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.
Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.
Description: The Validation Component of Apache Camel evaluates DTD headers of XML stream sources, although a validation against XML schemas (XSD) is executed. Remote attackers can use this feature to make Server-Side Request Forgery (SSRF) attacks by sending XML documents with remote DTDs URLs or XML External Entities (XXE). The vulnerability is not given for SAX or StAX sources.
Mitigation: 2.17.x users should upgrade to 2.17.6, 2.18.x users should upgrade to 2.18.3.
The JIRA tickets https://issues.apache.org/jira/browse/CAMEL-10894 refers to the various commits that resolved the issue, and have more details.
Red Hat
camel-core: Validation component vulnerable to SSRF via remote DTDs and XXE
vendor_redhat·2017-02-24·CVSS 7.4
CVE-2017-5643 [HIGH] CWE-918 camel-core: Validation component vulnerable to SSRF via remote DTDs and XXE
camel-core: Validation component vulnerable to SSRF via remote DTDs and XXE
Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.
It was found that Apache Camel's validation component evaluates DTD headers of XML stream sources, although a validation against XML schemas (XSD) is executed. Remote attackers can use this feature to make Server-Side Request Forgery (SSRF) attacks by sending XML documents with remote DTDs URLs or XML External Entities (XXE). The vulnerability is not given for SAX or StAX sources.
Package: camel (Red Hat JBoss A-MQ 6) - Affected
Package: camel-core (Red Hat JBoss BRMS 5) - Will not fix
Package: camel-core (Red Hat JBoss Data Grid 6) - Out of support scope
Package: camel-core (Red Hat JBoss Fuse Service Works 6) - Affected
Apache
Apache camel: CVE-2017-5643
vendor_apache·CVSS 7.4
CVE-2017-5643 [MEDIUM] Apache camel: CVE-2017-5643
Apache camel: CVE-2017-5643
2.17.0 up to 2.17.5, 2.18.0 up to 2.18.2 2.17.6, 2.18.3 and newer MEDIUM Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE
Severity: medium
No detection rules found.
No public exploits indexed.
http://camel.apache.org/security-advisories.data/CVE-2017-5643.txt.asc?version=1&modificationDate=1489652454000&api=v2http://www.securityfocus.com/bid/97226https://access.redhat.com/errata/RHSA-2017:1832https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3Ehttp://camel.apache.org/security-advisories.data/CVE-2017-5643.txt.asc?version=1&modificationDate=1489652454000&api=v2http://www.securityfocus.com/bid/97226https://access.redhat.com/errata/RHSA-2017:1832https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3E
2017-03-16
Published