Red Hat Bugzilla – Bug 1433374
CVE-2017-5643 camel-core: Validation component vulnerable to SSRF via remote DTDs and XXE
Last modified: 2018-06-29 18:19:06 EDT
The Validation Component of Apache Camel evaluates DTD headers of XML stream sources, although a validation against XML schemas (XSD) is executed. Remote attackers can use this feature to make Server-Side Request Forgery (SSRF) attacks by sending XML documents with remote DTDs URLs or XML External Entities (XXE). The vulnerability is not given for SAX or StAX sources. Versions Affected: Camel 2.17.0 to 2.17.5, Camel 2.18.0 to 2.18.2 The unsupported Camel 2.x (2.16 and earlier) versions may be also affected. External Reference: https://camel.apache.org/security-advisories.data/CVE-2017-5643.txt
This issue has been addressed in the following products: Red Hat JBoss Fuse Via RHSA-2017:1832 https://access.redhat.com/errata/RHSA-2017:1832