{"id":"GHSA-2fw5-rvf2-jq56","summary":"Apache Camel's XSLT component allows remote attackers to read arbitrary files","details":"The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other unspecified impact via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.","aliases":["CVE-2014-0002"],"modified":"2024-12-06T05:30:01.612779Z","published":"2018-10-16T23:13:26Z","database_specific":{"cwe_ids":[],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T20:51:56Z","nvd_published_at":"2014-03-21T04:38:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-0002"},{"type":"WEB","url":"https://github.com/apache/camel/commit/2ec54fa0c13ae65bdcccff764af081a79fcc05f"},{"type":"WEB","url":"https://github.com/apache/camel/commit/341d4e6cca71c53c90962d1c3d45fc9e05cc50c6"},{"type":"WEB","url":"https://github.com/apache/camel/commit/54b65c1d30848835f26bd138c0ba407bc1e560d"},{"type":"PACKAGE","url":"https://github.com/apache/camel"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/CAMEL-7129"},{"type":"WEB","url":"https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf@%3Ccommits.camel.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d@%3Ccommits.camel.apache.org%3E"},{"type":"WEB","url":"https://web.archive.org/web/20200229061309/http://www.securityfocus.com/bid/65901"},{"type":"WEB","url":"http://camel.apache.org/security-advisories.data/CVE-2014-0002.txt.asc"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-0371.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-0372.html"}],"affected":[{"package":{"name":"org.apache.camel:camel-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.camel/camel-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.11.4"}]}],"versions":["1.0.0","1.1.0","1.2.0","1.3.0","1.4.0","1.5.0","1.6.0","1.6.1","1.6.2","1.6.3","1.6.4","2.0-M1","2.0-M2","2.0-M3","2.0.0","2.1.0","2.10.0","2.10.1","2.10.2","2.10.3","2.10.4","2.10.5","2.10.6","2.10.7","2.11.0","2.11.1","2.11.2","2.11.3","2.2.0","2.3.0","2.4.0","2.5.0","2.6.0","2.7.0","2.7.1","2.7.2","2.7.3","2.7.4","2.7.5","2.8.0","2.8.1","2.8.2","2.8.3","2.8.4","2.8.5","2.8.6","2.9.0","2.9.0-RC1","2.9.1","2.9.2","2.9.3","2.9.4","2.9.5","2.9.6","2.9.7","2.9.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-2fw5-rvf2-jq56/GHSA-2fw5-rvf2-jq56.json"}},{"package":{"name":"org.apache.camel:camel-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.camel/camel-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.12.0"},{"fixed":"2.12.3"}]}],"versions":["2.12.0","2.12.1","2.12.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-2fw5-rvf2-jq56/GHSA-2fw5-rvf2-jq56.json"}}],"schema_version":"1.9.0"}