7.4
CVSSv3

CVE-2017-5643

Published: 16/03/2017 Updated: 07/11/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.4 | Impact Score: 4 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.

Vulnerable Product Search on Vulmon Subscribe to Product

apache camel 2.17.0

apache camel 2.17.2

apache camel 2.17.4

apache camel 2.17.3

apache camel 2.18.2

apache camel 2.17.5

apache camel 2.18.0

apache camel

apache camel 2.17.1

apache camel 2.18.1

Vendor Advisories

It was found that Apache Camel's validation component evaluates DTD headers of XML stream sources, although a validation against XML schemas (XSD) is executed Remote attackers can use this feature to make Server-Side Request Forgery (SSRF) attacks by sending XML documents with remote DTDs URLs or XML External Entities (XXE) The vulnerability is n ...