CVE-2018-8027
published 2018-07-31CVE-2018-8027: Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.
PriorityP349critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
5.52%
91.9th percentile
Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | 2.20.0 – 2.20.3 | — |
| apache_software_foundation | apache_camel | — | — |
| apache_software_foundation | apache_camel | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_apache9.8MEDIUM
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
camel-core: XXE in XSD validation processor
vendor_redhat·2018-07-31·CVSS 9.8
CVE-2018-8027 [CRITICAL] CWE-611 camel-core: XXE in XSD validation processor
camel-core: XXE in XSD validation processor
Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.
Package: camel-core (JBoss Developer Studio 11) - Not affected
Package: camel-core (Red Hat Fuse 7) - Not affected
Package: camel-core (Red Hat JBoss A-MQ 6) - Will not fix
Package: camel-core (Red Hat JBoss BRMS 5) - Out of support scope
Package: camel-core (Red Hat JBoss BRMS 6) - Out of support scope
Package: camel-core (Red Hat JBoss Data Grid 7) - Not affected
Package: camel-core (Red Hat JBoss Data Virtualization 6) - Out of support scope
Package: camel-core (Red Hat JBoss Fuse 6) - Will not fix
Package: camel-core (Red Hat JBoss Fuse Service Works 6) - Will not fix
Package: camel-core (Red Hat JBoss SOA Platform 4) - Not affected
Apache
Apache camel: CVE-2018-8027
vendor_apache·CVSS 9.8
CVE-2018-8027 [MEDIUM] Apache camel: CVE-2018-8027
Apache camel: CVE-2018-8027
2.20.0 up to 2.20.3, 2.21.0 2.20.4, 2.21.1 and newer MEDIUM Apache Camel's Core is vulnerable to XXE in XSD validation processor 2017
Severity: medium
GHSA
Apache is vulnerable to XXE in XSD validation processor
ghsa·2018-10-16
CVE-2018-8027 [CRITICAL] CWE-611 Apache is vulnerable to XXE in XSD validation processor
Apache is vulnerable to XXE in XSD validation processor
Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.
OSV
Apache is vulnerable to XXE in XSD validation processor
osv·2018-10-16
CVE-2018-8027 [CRITICAL] Apache is vulnerable to XXE in XSD validation processor
Apache is vulnerable to XXE in XSD validation processor
Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.
No detection rules found.
No public exploits indexed.
http://camel.apache.org/security-advisories.data/CVE-2018-8027.txt.aschttp://www.securityfocus.com/bid/104933https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/77f596fc63e63c2e9adcff3c34759b32c225cf0b582aedb755adaade%40%3Cdev.camel.apache.org%3Ehttps://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3Ehttp://camel.apache.org/security-advisories.data/CVE-2018-8027.txt.aschttp://www.securityfocus.com/bid/104933https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/77f596fc63e63c2e9adcff3c34759b32c225cf0b582aedb755adaade%40%3Cdev.camel.apache.org%3Ehttps://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3E
2018-07-31
Published