Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.apache.camel:camel-core(Maven) | 0 | 2.24.0 | N/A |
| org.apache.camel:camel-xmljson(Maven) | 0 | N/A | N/A |
CVSS Metrics