Uploaded image for project: 'JBeret'
  1. JBeret
  2. JBERET-456

Upgrade org.apache.camel:camel-core to version 2.17.6 or later to address vulnerability

    XMLWordPrintable

Details

    • Task
    • Resolution: Done
    • Major
    • 1.4.0.Final
    • 1.3.0.Final
    • jberet-camel
    • None

    Description

      See details at https://github.com/jberet/jsr352/network/alert/pom.xml/org.apache.camel:camel-core/open

      CVE-2017-5643
      moderate severity
      Vulnerable versions: < 2.17.6
      Patched version: 2.17.6
      Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.

      Attachments

        Activity

          People

            cfang@redhat.com Cheng Fang
            cfang@redhat.com Cheng Fang
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: