CVE-2014-0003: Apache Camel

High severity, CVSS 7.5. EPSS: 7.5% chance of exploitation in the next 30 days.

The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbitrary Java methods via a crafted message.

Affected products

  • Apache Camel: up to and including 2.11.3; version 1.0.0 only; version 1.1.0 only; version 1.2.0 only; version 1.3.0 only; version 1.4.0 only; …

Published 2014-03-21. Last modified 2026-06-17.