Apache Camel CVE-2014-0002 XML External Entity Information Disclosure Vulnerability
BID:65901
Info
Apache Camel CVE-2014-0002 XML External Entity Information Disclosure Vulnerability
| Bugtraq ID: | 65901 |
| Class: | Design Error |
| CVE: |
CVE-2014-0002 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 28 2014 12:00AM |
| Updated: | May 29 2014 01:54AM |
| Credit: | David Jorm |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Apache Camel CVE-2014-0002 XML External Entity Information Disclosure Vulnerability
Apache Camel is prone to an XML External Entity vulnerability.
An attacker can exploit this issue to gain access to sensitive information from the application; this may lead to further attacks.
The following versions are affected:
Apache Camel 2.11.0 through 2.11.3
Apache Camel 2.12.0 through 2.12.2
Apache Camel is prone to an XML External Entity vulnerability.
An attacker can exploit this issue to gain access to sensitive information from the application; this may lead to further attacks.
The following versions are affected:
Apache Camel 2.11.0 through 2.11.3
Apache Camel 2.12.0 through 2.12.2
Exploit / POC
Apache Camel CVE-2014-0002 XML External Entity Information Disclosure Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Apache Camel CVE-2014-0002 XML External Entity Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Camel CVE-2014-0002 XML External Entity Information Disclosure Vulnerability
References:
References: