The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other unspecified impact via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/57125 | third party advisory vendor advisory |
http://rhn.redhat.com/errata/RHSA-2014-0371.html | vendor advisory |
http://camel.apache.org/security-advisories.data/CVE-2014-0002.txt.asc | exploit vendor advisory |
http://secunia.com/advisories/57719 | third party advisory |
http://www.securityfocus.com/bid/65901 | vdb entry |
http://secunia.com/advisories/57716 | third party advisory |
http://rhn.redhat.com/errata/RHSA-2014-0372.html | vendor advisory |
https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3E | mailing list |
https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3E | mailing list |