CVE-2014-0002

The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other unspecified impact via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:1.5.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:1.6.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:1.6.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:1.6.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:1.6.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:1.6.4:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:2.0.0:milestone1:*:*:*:*:*:*
cpe:2.3:a:apache:camel:2.0.0:milestone2:*:*:*:*:*:*
cpe:2.3:a:apache:camel:2.0.0:milestone3:*:*:*:*:*:*
cpe:2.3:a:apache:camel:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:2.10.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:2.10.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:2.10.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:2.10.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:2.10.4:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:2.10.5:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:2.10.6:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:2.10.7:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:2.11.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:2.11.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:2.11.2:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:apache:camel:2.12.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:2.12.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:2.12.2:*:*:*:*:*:*:*

History

13 Feb 2023, 00:29

Type Values Removed Values Added
References
  • {'url': 'https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d@%3Ccommits.camel.apache.org%3E', 'name': '[camel-commits] 20190430 svn commit: r1044347 - in /websites/production/camel/content: cache/main.pageCache security-advisories.data/CVE-2019-0194.txt.asc security-advisories.html', 'tags': [], 'refsource': 'MLIST'}
  • {'url': 'https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf@%3Ccommits.camel.apache.org%3E', 'name': '[camel-commits] 20190524 svn commit: r1045395 - in /websites/production/camel/content: cache/main.pageCache security-advisories.data/CVE-2019-0188.txt.asc security-advisories.html', 'tags': [], 'refsource': 'MLIST'}
  • (MISC) https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3E -
  • (MISC) https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3E -

Information

Published : 2014-03-21 04:38

Updated : 2023-12-10 11:31


NVD link : CVE-2014-0002

Mitre link : CVE-2014-0002

CVE.ORG link : CVE-2014-0002


JSON object : View

Products Affected

apache

  • camel
CWE
CWE-264

Permissions, Privileges, and Access Controls