CVE-2019-0188: Apache Camel

High severity, CVSS 7.5. EPSS: 9.8% chance of exploitation in the next 30 days.

Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib library. This affects only the camel-xmljson component, which was removed.

Affected products

  • Apache Camel: before 2.24.0 (fixed in 2.24.0)
  • Oracle Enterprise Data Quality: version 11.1.1.9.0 only
  • Oracle Enterprise Manager Base Platform: version 13.3.0.0 only; version 13.4.0.0 only
  • Oracle Enterprise Repository: version 12.1.3.0.0 only
  • Oracle Flexcube Private Banking: version 12.0.0 only; version 12.1.0 only

Published 2019-05-28. Last modified 2026-06-17.