Vulnerability Database
Blog
FAQ
Docs
CVE-2017-5643
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2017-5643
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-5643.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2017-5643
Aliases
GHSA-vq9j-jh62-5hmp
Published
2017-03-16T15:59:00Z
Modified
2024-10-12T02:50:38.206056Z
Severity
7.4 (High)
CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
CVSS Calculator
Summary
[none]
Details
Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.
References
http://camel.apache.org/security-advisories.data/CVE-2017-5643.txt.asc?version=1&modificationDate=1489652454000&api=v2
http://www.securityfocus.com/bid/97226
https://access.redhat.com/errata/RHSA-2017:1832
https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3E
https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3E
Affected packages
Git
/
github.com/apache/camel
Affected ranges
Type
GIT
Repo
https://github.com/apache/camel
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Last affected
2123a4c74d66ef503d12bac4f37b941085e33345
Last affected
5a32be6497ee64782ab2b9f507033e5e6e5840b3
Last affected
8ed344875d0e2e60e9234c89888fec2f14945b0b
Last affected
a08cc255d6fd9148d652be52c25a4e95dcbff600
Last affected
af7064e6c1a754bb65eacb5f653bd551e4219cc6
Last affected
bf9c1455bd545848e2104027ce65624f148f41d8
Last affected
c3d54e2ff5c412ff9d663e6386c38eb9c18e2282
Last affected
cf2e1749fae7c2d7526c705eb2c9e45e7f8f1af4
Last affected
da8694f8c5392881ac5ab49c37a7947451bb65af
Last affected
dcd8a7ac69889d4067b772b09938261946808926
Affected versions
camel-2.*
camel-2.15.0
camel-2.16.0
camel-2.18.0
camel-2.18.1
camel-2.18.2
CVE-2017-5643 - OSV