Sploitus

CVE-2014-0002

1 known exploit for CVE-2014-0002

The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other unspecified impact via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Affected products
Apache Camel
Apache Camel
≤ 2.11.3, 1.0.0, 1.1.0, 1.2.0, 1.3.0, 1.4.0, 1.5.0, 1.6.0, 1.6.1, 1.6.2, 1.6.3, 1.6.4, 2.0.0, 2.1.0, 2.10.0, 2.10.1, 2.10.2, 2.10.3, 2.10.4, 2.10.5, 2.10.6, 2.10.7, 2.11.0, 2.11.1, 2.11.2
Fix
Available
CVSS 2.0
7.5 HIGH
EPSS
32.5% (98th percentile)
Weakness
CWE-264
NVD status
Modified
Published
2014-03-20
CVE-2014-0002 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2014-0002

Proof-of-concept code and exploit modules indexed by Sploitus