CVE-2019-0188: Apache Camel
High severity, CVSS 7.5. EPSS: 9.8% chance of exploitation in the next 30 days.
Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.
Affected products
- Apache Camel: before 2.24.0 (fixed in 2.24.0)
- Oracle Enterprise Data Quality: version 11.1.1.9.0 only
- Oracle Enterprise Manager Base Platform: version 13.3.0.0 only; version 13.4.0.0 only
- Oracle Enterprise Repository: version 12.1.3.0.0 only
- Oracle Flexcube Private Banking: version 12.0.0 only; version 12.1.0 only
Published 2019-05-28. Last modified 2026-06-17.