7.5
CVSSv2

CVE-2014-0002

Published: 21/03/2014 Updated: 13/02/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The XSLT component in Apache Camel prior to 2.11.4 and 2.12.x prior to 2.12.3 allows remote malicious users to read arbitrary files and possibly have other unspecified impact via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache camel 1.1.0

apache camel 2.0.0

apache camel 1.4.0

apache camel 2.10.6

apache camel

apache camel 1.2.0

apache camel 1.6.2

apache camel 2.10.0

apache camel 2.11.0

apache camel 2.10.7

apache camel 1.0.0

apache camel 2.10.4

apache camel 1.5.0

apache camel 2.11.2

apache camel 2.10.1

apache camel 1.6.1

apache camel 1.6.4

apache camel 2.10.3

apache camel 2.10.5

apache camel 1.6.0

apache camel 1.3.0

apache camel 2.11.1

apache camel 1.6.3

apache camel 2.1.0

apache camel 2.10.2

apache camel 2.12.1

apache camel 2.12.0

apache camel 2.12.2

Vendor Advisories

The XSLT component in Apache Camel before 2114 and 212x before 2123 allows remote attackers to read arbitrary files and possibly have other unspecified impact via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue ...