CVE-2015-0263
medium
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
5.0
Description
Apache Camel XML External Entity vulnerability
Predictions
Exploit likelihood
20%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | org.apache.camel:camel-core | <2.13.4 | 2.13.4 |
| Maven | org.apache.camel:camel-core | >=2.14.0,<2.14.2 | 2.14.2 |
References
- http://rhn.redhat.com/errata/RHSA-2015-1041.html
- http://rhn.redhat.com/errata/RHSA-2015-1538.html
- http://rhn.redhat.com/errata/RHSA-2015-1539.html
- http://www.securitytracker.com/id/1032442
- https://camel.apache.org/security-advisories.data/CVE-2015-0263.txt.asc
- https://git-wip-us.apache.org/repos/asf?p=camel.git%3Ba=commitdiff%3Bh=7d19340bcdb42f7aae584d9c5003ac4f7ddaee36
- https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3E
- https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2015-0263
- https://github.com/apache/camel/commit/06db9e0744f2bb9f6e3bf16c0dfe7099a3481558
- https://github.com/apache/camel/commit/367d53e73c8b5a1e73c24423e631709f9a96e08d
- https://github.com/apache/camel/commit/7d19340bcdb42f7aae584d9c5003ac4f7ddaee36
- https://git-wip-us.apache.org/repos/asf?p=camel.git;a=commitdiff;h=7d19340bcdb42f7aae584d9c5003ac4f7ddaee36
- https://github.com/advisories/GHSA-3hrc-f439-727g
- https://github.com/apache/camel
- https://issues.apache.org/jira/browse/CAMEL-8312
- https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf@%3Ccommits.camel.apache.org%3E
- https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d@%3Ccommits.camel.apache.org%3E
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.