cbcvebase.
CVE-2019-0188
published 2019-05-28

CVE-2019-0188: Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This…

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.

Affected

9 ranges
VendorProductVersion rangeFixed in
apacheapache_camel
apachecamel< 2.24.02.24.0
apachecamel
oracleenterprise_data_quality
oracleenterprise_manager_base_platform
oracleenterprise_manager_base_platform
oracleenterprise_repository
oracleflexcube_private_banking
oracleflexcube_private_banking