Apache ActiveMQ Apollo XML external entity Injection Vulnerability (CVE-2014-3579)
Release date:
Updated on:
Affected Systems:
Apache Group ActiveMQ Apollo
Description:
Bugtraq id: 72508
CVE (CAN) ID: CVE-2014-3579
Apache ActiveMQ Apollo is a simple, fast, and reliable message proxy derived from ActiveMQ.
Apache ActiveMQ Apollo has the XML external entity injection vulnerability. Attackers can exploit this vulnerability to perform unauthorized operations in the context of the affected application.
<* Source: & #195; Upper & #194; & #187; & #194; & #191; Georgi gesev
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://activemq.apache.org/apollo/
ActiveMQ installation in Linux
ACTIVEMQ server in Ubuntu
Spring + JMS + ActiveMQ + Tomcat Implement Message Service
Set ActiveMQ port and WEB port in Linux
This article permanently updates the link address: