Описание
Improper Restriction of XML External Entity Reference in Apache ActiveMQ
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2014-3600
- https://github.com/apache/activemq/commit/3e5ac6326db59f524a0e71f6b717428607d7b67d
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100722
- https://github.com/apache/activemq
- https://issues.apache.org/jira/browse/AMQ-5333
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2@%3Ccommits.activemq.apache.org%3E
- http://activemq.apache.org/security-advisories.data/CVE-2014-3600-announcement.txt
- http://seclists.org/oss-sec/2015/q1/427
Пакеты
org.apache.activemq:activemq-client
>= 5.0.0, < 5.10.1
5.10.1
org.apache.activemq:activemq-broker
>= 5.0.0, < 5.10.1
5.10.1
Связанные уязвимости
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before ...
Уязвимость программной платформы Apache ActiveMQ, связанная с некорректным ограничением XML-ссылок на внешние объекты, позволяющая нарушителю раскрыть защищаемую информацию, вызвать отказ в обслуживании или оказать другое воздействие