Release date:
Updated on:
Affected Systems:
Apache Group Camel <2.12.3
Apache Group Camel <2.11.4
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-0002
Apache Camel is an open-source integration framework based on a known enterprise-level integration model.
The XSLT components of Apache Camel 2.11.0-2.11.3 and Apache Camel 2.12.0-2.12.2 use xslt routines to parse entities in the message when converting XML messages, remote attackers who can submit messages to xslt routines can exploit this vulnerability to read accessible files on the running application server, or perform other advanced XXE attacks.
<* Source: David Jorm
Link: http://secunia.com/advisories/57125/
Http://camel.apache.org/security-advisories.data/CVE-2014-0002.txt.asc
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apache Group
------------
Apache Group has released a Security Bulletin (CVE-2014-0002) and patches for this:
CVE-2014-0002: CVE-2014-0002: Apache Camel critical disclosure vulnerability
Link: http://camel.apache.org/security-advisories.data/CVE-2014-0002.txt.asc