Vulnerability Description
Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Camel | < 2.24.0 |
| Oracle | Enterprise Data Quality | 11.1.1.9.0 |
| Oracle | Enterprise Manager Base Platform | 13.3.0.0 |
| Oracle | Flexcube Private Banking | 12.0.0 |
| Oracle | Enterprise Repository | 12.1.3.0.0 |
Related Weaknesses (CWE)
References
- http://jvn.jp/en/jp/JVN71498764/index.htmlThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2019/05/24/2Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/108422Third Party AdvisoryVDB Entry
- https://github.com/apache/camel/blob/master/docs/user-manual/en/security-advisorBroken Link
- https://lists.apache.org/thread.html/00118387610522b107cbdcec5369ddd512b576ff023
- https://lists.apache.org/thread.html/45349f8bd98c1c13a84beddede18fe79b8619ebab99
- https://lists.apache.org/thread.html/61601cda2c5f9832184ea14647b0c0589c94126a460
- https://lists.apache.org/thread.html/63d1cec8541befeb59dbed23a6b227bdcca7674aa23
- https://lists.apache.org/thread.html/6fefbd90f7fb4c8412d85ea3e9e97a4b76b47e206f5
- https://lists.apache.org/thread.html/84ba9b79e801a4148dde73d1969cdae0247d11ff63d
- https://lists.apache.org/thread.html/ac51944aef91dd5006b8510b0bef337adaccfe962fb
- https://lists.apache.org/thread.html/eed73fc18d4fa3e2341cd0ab101b47f06b16c7efc1c
- https://lists.apache.org/thread.html/fe74d173689600d9a395d026f0bf5d154c0bf7bd195
- https://www.oracle.com/security-alerts/cpujan2021.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlThird Party Advisory
FAQ
What is CVE-2019-0188?
CVE-2019-0188 is a vulnerability with a CVSS score of 7.5 (HIGH). Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component...
How severe is CVE-2019-0188?
CVE-2019-0188 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-0188?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Camel, Oracle Enterprise Data Quality, Oracle Enterprise Manager Base Platform, Oracle Flexcube Private Banking, Oracle Enterprise Repository.