Apache Camel-XMLJson vulnerable to XML external entity injection (XXE)
Versions affected
Apache Camel versions prior to 2.24.0
Versions fixed
2.24.0
Description
Apache Camel provided contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.