Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3208

Опубликовано: 23 июл. 2015
Источник: redhat
CVSS2: 4.3

Описание

An XML External Entity (XXE) Injection vulnerability was reported in the XPath component of HornetQ.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7artemisNot affected
Red Hat JBoss Enterprise Application Platform 5hornetqNot affected
Red Hat JBoss Enterprise Application Platform 6hornetqNot affected
Red Hat Satellite 6hornetqWill not fix
Red Hat Subscription Asset ManagerhornetqWill not fix
Red Hat Satellite 6.4 for RHEL 7ansiblerole-insights-clientFixedRHSA-2018:292716.10.2018
Red Hat Satellite 6.4 for RHEL 7candlepinFixedRHSA-2018:292716.10.2018
Red Hat Satellite 6.4 for RHEL 7createrepo_cFixedRHSA-2018:292716.10.2018
Red Hat Satellite 6.4 for RHEL 7foremanFixedRHSA-2018:292716.10.2018
Red Hat Satellite 6.4 for RHEL 7foreman-bootloaders-redhatFixedRHSA-2018:292716.10.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1225252hornetq: XXE/SSRF in XPath selector

4.3 Medium

CVSS2

Связанные уязвимости

nvd
больше 8 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

CVSS3: 9.8
github
больше 3 лет назад

Withdrawn Advisory: Improper Restriction of XML External Entity Reference in Apache ActiveMQ

4.3 Medium

CVSS2