XML External Entity Vulnerability in Apache Camel Products
CVE-2014-0002

Currently unrated

Key Information:

Vendor
Apache
Status
Vendor
CVE Published:
21 March 2014

Summary

The XSLT component in Apache Camel versions prior to 2.11.4 and 2.12.x before 2.12.3 is susceptible to an XML External Entity (XXE) vulnerability. This flaw permits remote attackers to exploit the system by crafting a malicious XML document that includes external entity declarations. Such exploitation can lead to unauthorized file reading and other undefined impacts, potentially compromising sensitive information or leading to further attacks on the system.

References

EPSS Score

34% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.