Apache Camel's Core versions 2.20.0 to 2.20.3 and 2.21.0 is vulnerable to XXE External Entity vulnerability XSD validation processor. Upstream bug: https://issues.apache.org/jira/browse/CAMEL-12444 https://issues.apache.org/jira/browse/CAMEL-10894 References: https://lists.apache.org/thread.html/77f596fc63e63c2e9adcff3c34759b32c225cf0b582aedb755adaade@%3Cdev.camel.apache.org%3E
This vulnerability is out of security support scope for the following products: * Red Hat JBoss BRMS 6 * Red Hat JBoss Data Virtualization & Services 6 * Red Hat JBoss BRMS 5 Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2018-8027