{"document":{"aggregate_severity":{"namespace":"https://access.redhat.com/security/updates/classification/","text":"Important"},"category":"csaf_vex","csaf_version":"2.0","distribution":{"text":"Copyright © Red Hat, Inc. All rights reserved.","tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en","notes":[{"category":"legal_disclaimer","text":"This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.","title":"Terms of Use"}],"publisher":{"category":"vendor","contact_details":"https://access.redhat.com/security/team/contact/","issuing_authority":"Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.","name":"Red Hat Product Security","namespace":"https://www.redhat.com"},"references":[{"category":"self","summary":"Canonical URL","url":"https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-28168.json"}],"title":"fop: Improper Restriction of XML External Entity Reference ('XXE')","tracking":{"current_release_date":"2026-01-12T20:09:03+00:00","generator":{"date":"2026-01-12T20:09:03+00:00","engine":{"name":"Red Hat SDEngine","version":"4.6.14"}},"id":"CVE-2024-28168","initial_release_date":"2024-10-09T12:15:02.850000+00:00","revision_history":[{"date":"2024-10-09T12:15:02.850000+00:00","number":"1","summary":"Initial version"},{"date":"2025-07-10T08:09:19+00:00","number":"2","summary":"Current version"},{"date":"2026-01-12T20:09:03+00:00","number":"3","summary":"Last generated version"}],"status":"final","version":"3"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"Red Hat build of Apache Camel for Spring Boot 3","product":{"name":"Red Hat build of Apache Camel for Spring Boot 3","product_id":"red_hat_build_of_apache_camel_for_spring_boot_3","product_identification_helper":{"cpe":"cpe:/a:redhat:camel_spring_boot:3"}}}],"category":"product_family","name":"Red Hat build of Apache Camel for Spring Boot 3"},{"branches":[{"category":"product_name","name":"Red Hat build of Apache Camel for Spring Boot 4","product":{"name":"Red Hat build of Apache Camel for Spring Boot 4","product_id":"red_hat_build_of_apache_camel_for_spring_boot_4","product_identification_helper":{"cpe":"cpe:/a:redhat:camel_spring_boot:4"}}}],"category":"product_family","name":"Red Hat build of Apache Camel for Spring Boot 4"},{"branches":[{"category":"product_name","name":"Red Hat build of OptaPlanner 8","product":{"name":"Red Hat build of OptaPlanner 8","product_id":"red_hat_build_of_optaplanner_8","product_identification_helper":{"cpe":"cpe:/a:redhat:optaplanner:::el6"}}}],"category":"product_family","name":"Red Hat build of OptaPlanner 8"},{"branches":[{"category":"product_name","name":"Red Hat Fuse 7","product":{"name":"Red Hat Fuse 7","product_id":"red_hat_fuse_7","product_identification_helper":{"cpe":"cpe:/a:redhat:jboss_fuse:7"}}}],"category":"product_family","name":"Red Hat Fuse 7"},{"branches":[{"category":"product_name","name":"Red Hat Integration Camel K 1","product":{"name":"Red Hat Integration Camel K 1","product_id":"red_hat_integration_camel_k_1","product_identification_helper":{"cpe":"cpe:/a:redhat:integration:1"}}}],"category":"product_family","name":"Red Hat Integration Camel K 1"},{"branches":[{"category":"product_name","name":"Red Hat JBoss Data Grid 7","product":{"name":"Red Hat JBoss Data Grid 7","product_id":"red_hat_jboss_data_grid_7","product_identification_helper":{"cpe":"cpe:/a:redhat:jboss_data_grid:7"}}}],"category":"product_family","name":"Red Hat JBoss Data Grid 7"},{"branches":[{"category":"product_name","name":"Red Hat JBoss Enterprise Application Platform 7","product":{"name":"Red Hat JBoss Enterprise Application Platform 7","product_id":"red_hat_jboss_enterprise_application_platform_7","product_identification_helper":{"cpe":"cpe:/a:redhat:jboss_enterprise_application_platform:7"}}}],"category":"product_family","name":"Red Hat JBoss Enterprise Application Platform 7"},{"branches":[{"category":"product_name","name":"Red Hat JBoss Enterprise Application Platform 8","product":{"name":"Red Hat JBoss Enterprise Application Platform 8","product_id":"red_hat_jboss_enterprise_application_platform_8","product_identification_helper":{"cpe":"cpe:/a:redhat:jboss_enterprise_application_platform:8"}}}],"category":"product_family","name":"Red Hat JBoss Enterprise Application Platform 8"},{"branches":[{"category":"product_name","name":"Red Hat JBoss Enterprise Application Platform Expansion Pack","product":{"name":"Red Hat JBoss Enterprise Application Platform Expansion Pack","product_id":"red_hat_jboss_enterprise_application_platform_expansion_pack","product_identification_helper":{"cpe":"cpe:/a:redhat:jbosseapxp"}}}],"category":"product_family","name":"Red Hat JBoss Enterprise Application Platform Expansion Pack"},{"branches":[{"category":"product_name","name":"Red Hat Process Automation 7","product":{"name":"Red Hat Process Automation 7","product_id":"red_hat_process_automation_7","product_identification_helper":{"cpe":"cpe:/a:redhat:jboss_enterprise_bpms_platform:7"}}}],"category":"product_family","name":"Red Hat Process Automation 7"},{"category":"product_version","name":"org.apache.xmlgraphics/fop","product":{"name":"org.apache.xmlgraphics/fop","product_id":"org.apache.xmlgraphics/fop"}},{"category":"product_version","name":"fop","product":{"name":"fop","product_id":"fop","product_identification_helper":{"purl":"pkg:maven/org.apache.xmlgraphics/fop"}}}],"category":"vendor","name":"Red Hat"}],"relationships":[{"category":"default_component_of","full_product_name":{"name":"org.apache.xmlgraphics/fop as a component of Red Hat build of Apache Camel for Spring Boot 3","product_id":"red_hat_build_of_apache_camel_for_spring_boot_3:org.apache.xmlgraphics/fop"},"product_reference":"org.apache.xmlgraphics/fop","relates_to_product_reference":"red_hat_build_of_apache_camel_for_spring_boot_3"},{"category":"default_component_of","full_product_name":{"name":"org.apache.xmlgraphics/fop as a component of Red Hat build of Apache Camel for Spring Boot 4","product_id":"red_hat_build_of_apache_camel_for_spring_boot_4:org.apache.xmlgraphics/fop"},"product_reference":"org.apache.xmlgraphics/fop","relates_to_product_reference":"red_hat_build_of_apache_camel_for_spring_boot_4"},{"category":"default_component_of","full_product_name":{"name":"org.apache.xmlgraphics/fop as a component of Red Hat build of OptaPlanner 8","product_id":"red_hat_build_of_optaplanner_8:org.apache.xmlgraphics/fop"},"product_reference":"org.apache.xmlgraphics/fop","relates_to_product_reference":"red_hat_build_of_optaplanner_8"},{"category":"default_component_of","full_product_name":{"name":"org.apache.xmlgraphics/fop as a component of Red Hat Fuse 7","product_id":"red_hat_fuse_7:org.apache.xmlgraphics/fop"},"product_reference":"org.apache.xmlgraphics/fop","relates_to_product_reference":"red_hat_fuse_7"},{"category":"default_component_of","full_product_name":{"name":"org.apache.xmlgraphics/fop as a component of Red Hat Integration Camel K 1","product_id":"red_hat_integration_camel_k_1:org.apache.xmlgraphics/fop"},"product_reference":"org.apache.xmlgraphics/fop","relates_to_product_reference":"red_hat_integration_camel_k_1"},{"category":"default_component_of","full_product_name":{"name":"org.apache.xmlgraphics/fop as a component of Red Hat JBoss Data Grid 7","product_id":"red_hat_jboss_data_grid_7:org.apache.xmlgraphics/fop"},"product_reference":"org.apache.xmlgraphics/fop","relates_to_product_reference":"red_hat_jboss_data_grid_7"},{"category":"default_component_of","full_product_name":{"name":"fop as a component of Red Hat JBoss Enterprise Application Platform 7","product_id":"red_hat_jboss_enterprise_application_platform_7:fop"},"product_reference":"fop","relates_to_product_reference":"red_hat_jboss_enterprise_application_platform_7"},{"category":"default_component_of","full_product_name":{"name":"fop as a component of Red Hat JBoss Enterprise Application Platform 8","product_id":"red_hat_jboss_enterprise_application_platform_8:fop"},"product_reference":"fop","relates_to_product_reference":"red_hat_jboss_enterprise_application_platform_8"},{"category":"default_component_of","full_product_name":{"name":"fop as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack","product_id":"red_hat_jboss_enterprise_application_platform_expansion_pack:fop"},"product_reference":"fop","relates_to_product_reference":"red_hat_jboss_enterprise_application_platform_expansion_pack"},{"category":"default_component_of","full_product_name":{"name":"org.apache.xmlgraphics/fop as a component of Red Hat Process Automation 7","product_id":"red_hat_process_automation_7:org.apache.xmlgraphics/fop"},"product_reference":"org.apache.xmlgraphics/fop","relates_to_product_reference":"red_hat_process_automation_7"}]},"vulnerabilities":[{"cve":"CVE-2024-28168","cwe":{"id":"CWE-611","name":"Improper Restriction of XML External Entity Reference"},"discovery_date":"2024-10-09T12:20:12.072577+00:00","flags":[{"label":"vulnerable_code_not_present","product_ids":["red_hat_build_of_apache_camel_for_spring_boot_3:org.apache.xmlgraphics/fop","red_hat_build_of_apache_camel_for_spring_boot_4:org.apache.xmlgraphics/fop","red_hat_jboss_data_grid_7:org.apache.xmlgraphics/fop","red_hat_jboss_enterprise_application_platform_7:fop","red_hat_jboss_enterprise_application_platform_8:fop"]},{"label":"component_not_present","product_ids":["red_hat_build_of_optaplanner_8:org.apache.xmlgraphics/fop","red_hat_process_automation_7:org.apache.xmlgraphics/fop"]}],"ids":[{"system_name":"Red Hat Bugzilla ID","text":"2317557"}],"notes":[{"category":"description","text":"A flaw was found in Apache XML Graphics FOP. This vulnerability allows remote attackers to cause issues via improper handling of XML External Entity (XXE) references.","title":"Vulnerability description"},{"category":"summary","text":"fop: Improper Restriction of XML External Entity Reference ('XXE')","title":"Vulnerability summary"},{"category":"other","text":"The XXE vulnerability in Apache XML Graphics FOP is considered important rather than moderate due to its potential to compromise the confidentiality, integrity, and availability of a system. XXE flaws can be exploited to access sensitive internal files, such as configuration or credential files, leading to data exposure without authorization. Additionally, XXE attacks may enable attackers to perform server-side request forgery (SSRF), allowing them to make unauthorized requests to internal systems or services, potentially pivoting within a network.\n\nRed Hat build of Apache Camel for Springboot ships the affected component but it is not a supported library, hence the will not fix state.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"known_affected":["red_hat_fuse_7:org.apache.xmlgraphics/fop","red_hat_integration_camel_k_1:org.apache.xmlgraphics/fop","red_hat_jboss_enterprise_application_platform_expansion_pack:fop"],"known_not_affected":["red_hat_build_of_apache_camel_for_spring_boot_3:org.apache.xmlgraphics/fop","red_hat_build_of_apache_camel_for_spring_boot_4:org.apache.xmlgraphics/fop","red_hat_build_of_optaplanner_8:org.apache.xmlgraphics/fop","red_hat_jboss_data_grid_7:org.apache.xmlgraphics/fop","red_hat_jboss_enterprise_application_platform_7:fop","red_hat_jboss_enterprise_application_platform_8:fop","red_hat_process_automation_7:org.apache.xmlgraphics/fop"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2024-28168"},{"category":"external","summary":"RHBZ#2317557","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2317557"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2024-28168","url":"https://www.cve.org/CVERecord?id=CVE-2024-28168"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2024-28168","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-28168"},{"category":"external","summary":"https://xmlgraphics.apache.org/security.html","url":"https://xmlgraphics.apache.org/security.html"}],"release_date":"2024-10-09T12:15:02.850000+00:00","remediations":[{"category":"workaround","details":"Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.","product_ids":["red_hat_build_of_apache_camel_for_spring_boot_3:org.apache.xmlgraphics/fop","red_hat_build_of_apache_camel_for_spring_boot_4:org.apache.xmlgraphics/fop","red_hat_build_of_optaplanner_8:org.apache.xmlgraphics/fop","red_hat_fuse_7:org.apache.xmlgraphics/fop","red_hat_integration_camel_k_1:org.apache.xmlgraphics/fop","red_hat_jboss_data_grid_7:org.apache.xmlgraphics/fop","red_hat_jboss_enterprise_application_platform_7:fop","red_hat_jboss_enterprise_application_platform_8:fop","red_hat_jboss_enterprise_application_platform_expansion_pack:fop","red_hat_process_automation_7:org.apache.xmlgraphics/fop"]},{"category":"no_fix_planned","details":"Will not fix","product_ids":["red_hat_fuse_7:org.apache.xmlgraphics/fop","red_hat_integration_camel_k_1:org.apache.xmlgraphics/fop"]},{"category":"none_available","details":"Affected","product_ids":["red_hat_jboss_enterprise_application_platform_expansion_pack:fop"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["red_hat_build_of_apache_camel_for_spring_boot_3:org.apache.xmlgraphics/fop","red_hat_build_of_apache_camel_for_spring_boot_4:org.apache.xmlgraphics/fop","red_hat_build_of_optaplanner_8:org.apache.xmlgraphics/fop","red_hat_fuse_7:org.apache.xmlgraphics/fop","red_hat_integration_camel_k_1:org.apache.xmlgraphics/fop","red_hat_jboss_data_grid_7:org.apache.xmlgraphics/fop","red_hat_jboss_enterprise_application_platform_7:fop","red_hat_jboss_enterprise_application_platform_8:fop","red_hat_jboss_enterprise_application_platform_expansion_pack:fop","red_hat_process_automation_7:org.apache.xmlgraphics/fop"]}],"threats":[{"category":"impact","details":"Important","product_ids":["red_hat_build_of_apache_camel_for_spring_boot_3:org.apache.xmlgraphics/fop","red_hat_build_of_apache_camel_for_spring_boot_4:org.apache.xmlgraphics/fop","red_hat_build_of_optaplanner_8:org.apache.xmlgraphics/fop","red_hat_fuse_7:org.apache.xmlgraphics/fop","red_hat_integration_camel_k_1:org.apache.xmlgraphics/fop","red_hat_jboss_data_grid_7:org.apache.xmlgraphics/fop","red_hat_jboss_enterprise_application_platform_7:fop","red_hat_jboss_enterprise_application_platform_8:fop","red_hat_jboss_enterprise_application_platform_expansion_pack:fop","red_hat_process_automation_7:org.apache.xmlgraphics/fop"]}],"title":"fop: Improper Restriction of XML External Entity Reference ('XXE')"}]}