CVE-2017-5643

HIGH

Apache Camel < 2.16.0 - Server-Side Request Forgery via Remote DTDs

Title source: llm
STIX 2.1

Description

Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.

Scores

CVSS v3 7.4
EPSS 0.0140
EPSS Percentile 80.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N

Details

CWE
CWE-918
Status published
Products (14)
apache/camel 2.17.0
apache/camel 2.17.1
apache/camel 2.17.2
apache/camel 2.17.3
apache/camel 2.17.4
apache/camel 2.17.5
apache/camel 2.18.0
apache/camel 2.18.1
apache/camel 2.18.2
apache/camel < 2.16.0
... and 4 more
Published Mar 16, 2017
Tracked Since Feb 18, 2026