Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mhx2-r3jx-g94c

Опубликовано: 16 окт. 2018
Источник: github
Github: Прошло ревью

Описание

Apache Camel allows remote actor to read arbitrary files via external entity in invalid XML string or GenericFile object

Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an invalid XML (1) String or (2) GenericFile object in an XPath query.

Пакеты

Наименование

org.apache.camel:camel-core

maven
Затронутые версииВерсия исправления

< 2.13.4

2.13.4

Наименование

org.apache.camel:camel-core

maven
Затронутые версииВерсия исправления

>= 2.14.0, < 2.14.2

2.14.2

EPSS

Процентиль: 83%
0.02016
Низкий

Связанные уязвимости

redhat
почти 11 лет назад

Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an invalid XML (1) String or (2) GenericFile object in an XPath query.

nvd
больше 10 лет назад

Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an invalid XML (1) String or (2) GenericFile object in an XPath query.

EPSS

Процентиль: 83%
0.02016
Низкий