Apache ActiveMQ Apollo CVE-2014-3579 XML External Entity Injection Vulnerability
BID:72508
Info
Apache ActiveMQ Apollo CVE-2014-3579 XML External Entity Injection Vulnerability
| Bugtraq ID: | 72508 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3579 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 05 2015 12:00AM |
| Updated: | Jul 15 2015 12:45AM |
| Credit: | Georgi Geshev from MWR Labs |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Apache ActiveMQ Apollo CVE-2014-3579 XML External Entity Injection Vulnerability
Apache ActiveMQ Apollo is prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to perform unauthorized actions in the context of the affected application.
Apache ActiveMQ Apollo is prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to perform unauthorized actions in the context of the affected application.
Exploit / POC
Apache ActiveMQ Apollo CVE-2014-3579 XML External Entity Injection Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
Apache ActiveMQ Apollo CVE-2014-3579 XML External Entity Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache ActiveMQ Apollo CVE-2014-3579 XML External Entity Injection Vulnerability
References:
References: