Apache Camel security advisory
CVE-2018-8027
Apache Camel's Core is vulnerable to XXE in XSD validation processor
Description
Apache Camel's Core is vulnerable to XXE External Entity vulnerability XSD validation processor.
Mitigation
2.20.x users should upgrade to 2.20.4, 2.21.0 users should upgrade to 2.21.1. The JIRA tickets: https://issues.apache.org/jira/browse/CAMEL-12444 and https://issues.apache.org/jira/browse/CAMEL-10894 (partial fix) refer to the various commits that resovoled the issue, and have more details.
Credit
This issue was discovered by Karel JelĂnek <karel dot jelinek at unicorn dot com> from Unicorn Systems.
Notes
The JIRA tickets: https://issues.apache.org/jira/browse/CAMEL-12444 and https://issues.apache.org/jira/browse/CAMEL-10894 (partial fix) refer to the various commits that resovoled the issue, and have more details.