Vulnerability Database
Blog
FAQ
Docs
CVE-2018-8027
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2018-8027
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-8027.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-8027
Aliases
GHSA-8vfm-4388-6rpc
Published
2018-07-31T13:29:00Z
Modified
2024-09-03T02:22:12.472793Z
Severity
9.8 (Critical)
CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Calculator
Summary
[none]
Details
Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.
References
http://camel.apache.org/security-advisories.data/CVE-2018-8027.txt.asc
http://www.securityfocus.com/bid/104933
https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3E
https://lists.apache.org/thread.html/77f596fc63e63c2e9adcff3c34759b32c225cf0b582aedb755adaade%40%3Cdev.camel.apache.org%3E
https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3E
Affected packages
Git
/
github.com/apache/camel
Affected ranges
Type
GIT
Repo
https://github.com/apache/camel
Events
Introduced
aff4434eb839e9d690a0419230264b14a0ddeb22
Last affected
32bfda73ddd1ea8576bcb53dac496af9e0825f1a
Last affected
36bea62e844c5037b8c4d9e0eab5cc6b189fe1da
Affected versions
camel-2.*
camel-2.20.0
camel-2.20.1
camel-2.20.3
CVE-2018-8027 - OSV