CVE-2014-0002
15Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackepss 33%
probabilidade de exploração
33%top 2% das CVEs
exploração observada
nãonenhuma fonte reporta
The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other unspecified impact via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Produtos afetados
n/a · n/aReferências
http://camel.apache.org/security-advisories.data/CVE-2014-0002.txt.aschttp://rhn.redhat.com/errata/RHSA-2014-0371.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0372.htmlhttp://secunia.com/advisories/57125http://secunia.com/advisories/57716http://secunia.com/advisories/57719https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3Ehttp://www.securityfocus.com/bid/65901