CVE-2014-3629
published 2014-11-17CVE-2014-3629: XML external entity (XXE) vulnerability in the XML Exchange module in Apache Qpid 0.30 allows remote attackers to cause outgoing HTTP connections via a crafted…
PriorityP429medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
6.92%
93.3th percentile
XML external entity (XXE) vulnerability in the XML Exchange module in Apache Qpid 0.30 allows remote attackers to cause outgoing HTTP connections via a crafted message.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | qpid | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mm2c-whrj-39qm: XML external entity (XXE) vulnerability in the XML Exchange module in Apache Qpid 0
ghsa_unreviewed·2022-05-14
CVE-2014-3629 [MEDIUM] GHSA-mm2c-whrj-39qm: XML external entity (XXE) vulnerability in the XML Exchange module in Apache Qpid 0
XML external entity (XXE) vulnerability in the XML Exchange module in Apache Qpid 0.30 allows remote attackers to cause outgoing HTTP connections via a crafted message.
OSV
CVE-2014-3629: XML external entity (XXE) vulnerability in the XML Exchange module in Apache Qpid 0
osv·2014-11-17·CVSS 4.3
CVE-2014-3629 [MEDIUM] CVE-2014-3629: XML external entity (XXE) vulnerability in the XML Exchange module in Apache Qpid 0
XML external entity (XXE) vulnerability in the XML Exchange module in Apache Qpid 0.30 allows remote attackers to cause outgoing HTTP connections via a crafted message.
Red Hat
qpid-cpp: XXE vulnerability causes outgoing HTTP connections
vendor_redhat·2014-11-07·CVSS 4.3
CVE-2014-3629 [MEDIUM] qpid-cpp: XXE vulnerability causes outgoing HTTP connections
qpid-cpp: XXE vulnerability causes outgoing HTTP connections
XML external entity (XXE) vulnerability in the XML Exchange module in Apache Qpid 0.30 allows remote attackers to cause outgoing HTTP connections via a crafted message.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: qpid-cpp (Red Hat Enterprise Linux 6) - Affected
Package: qpid-cpp (Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7) - Under investigation
Package: qpid-cpp (Red Hat Enterprise MRG 2) - Affected
Package: qpid-cpp (Red Hat Enterprise MRG 3) -
No detection rules found.
No public exploits indexed.
http://packetstormsecurity.com/files/129034/Apache-Qpid-0.30-Induced-HTTP-Requests.htmlhttp://secunia.com/advisories/62235http://www.securityfocus.com/archive/1/533943/100/0/threadedhttp://www.securityfocus.com/bid/71004https://exchange.xforce.ibmcloud.com/vulnerabilities/98575http://packetstormsecurity.com/files/129034/Apache-Qpid-0.30-Induced-HTTP-Requests.htmlhttp://secunia.com/advisories/62235http://www.securityfocus.com/archive/1/533943/100/0/threadedhttp://www.securityfocus.com/bid/71004https://exchange.xforce.ibmcloud.com/vulnerabilities/98575
2014-11-17
Published