Impact
The vulnerability stems from an improper restriction of XML External Entity (XEE) references in the XSLT support extension of Apache Camel Quarkus. By supplying an XML document that contains external entity declarations, an attacker can cause the Xalan‑backed TransformerFactory to read local files or send requests to internal network locations. This flaw allows sensitive data leakage from the target system without needing to execute code outside the application context. The weakness is classified as CWE‑611, indicating that external DTD or stylesheet access controls are not correctly enforced.
Affected Systems
The issue affects applications that include any of the following Camel Quarkus extensions: camel‑quarkus‑xslt, camel‑quarkus‑xslt‑saxon, camel‑quarkus‑tika, camel‑quarkus‑xmlsecurity, and specifically the Xalan‑based XSLT support extension camel‑quarkus‑support‑xalan. All platforms running Apache Camel Quarkus version 3.2.0 up to but not including 3.33.3, and versions 3.34.0 up to but not including 3.40.0 are vulnerable.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity, and the EPSS score is not available, with the vulnerability not listed in CISA KEV. Based on the description, it is inferred that an attacker who can supply a crafted XML document to the application—such as through a remote interface that accepts XML—could trigger the flaw. Because the vulnerability can be induced by providing crafted XML to any component that performs XSLT transformations, it can potentially be exploited remotely over a network connection that offers XML input. The vulnerability is active in the JAXP default factory, meaning that any application code invoking TransformerFactory.newInstance() in the same runtime will inherit the same unprotected access rights, expanding the attack surface.
OpenCVE Enrichment