CVE-2015-0264
published 2015-06-03CVE-2015-0264: Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote…
PriorityP336medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
7.09%
93.5th percentile
Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an invalid XML (1) String or (2) GenericFile object in an XPath query.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | camel | <= 2.13.3 | — |
| apache | camel | — | — |
| apache | camel | — | — |
| apache | camel | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_apache5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Camel allows remote actor to read arbitrary files via external entity in invalid XML string or GenericFile object
ghsa·2018-10-16
CVE-2015-0264 [MEDIUM] Apache Camel allows remote actor to read arbitrary files via external entity in invalid XML string or GenericFile object
Apache Camel allows remote actor to read arbitrary files via external entity in invalid XML string or GenericFile object
Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an invalid XML (1) String or (2) GenericFile object in an XPath query.
OSV
Apache Camel allows remote actor to read arbitrary files via external entity in invalid XML string or GenericFile object
osv·2018-10-16
CVE-2015-0264 [MEDIUM] Apache Camel allows remote actor to read arbitrary files via external entity in invalid XML string or GenericFile object
Apache Camel allows remote actor to read arbitrary files via external entity in invalid XML string or GenericFile object
Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an invalid XML (1) String or (2) GenericFile object in an XPath query.
Red Hat
Camel: XXE via XPath expression evaluation
vendor_redhat·2015-03-17·CVSS 5.0
CVE-2015-0264 [MEDIUM] CWE-611 Camel: XXE via XPath expression evaluation
Camel: XXE via XPath expression evaluation
Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an invalid XML (1) String or (2) GenericFile object in an XPath query.
It was found that Apache Camel performed XML External Entity (XXE) expansion when evaluating invalid XML Strings or invalid XML GenericFile objects. A remote attacker able to submit a crafted XML message could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.
Package: camel (OpenShift Enterprise 1) - Will not fix
Package: camel (Red Hat OpenShift Enterprise 2) - Affected
Apache
Apache camel: CVE-2015-0264
vendor_apache·CVSS 5.0
CVE-2015-0264 [MEDIUM] Apache camel: CVE-2015-0264
Apache camel: CVE-2015-0264
2.13.0 up to 2.13.3, 2.14.0 up to 2.14.1 2.13.4, 2.14.2, 2.15.0 and newer MEDIUM The XPath handling in Apache Camel for invalid XML Strings or invalid XML GenericFile objects allows remote attackers to read arbitrary files via an XML External Entity (XXE) declaration. The XML External Entity (XXE) will be resolved before the Exception is thrown.
Severity: medium
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2015-1041.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1538.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1539.htmlhttp://securitytracker.com/id/1032442https://camel.apache.org/security-advisories.data/CVE-2015-0264.txt.aschttps://git-wip-us.apache.org/repos/asf?p=camel.git%3Ba=commitdiff%3Bh=1df559649a96a1ca0368373387e542f46e4820dahttps://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3Ehttp://rhn.redhat.com/errata/RHSA-2015-1041.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1538.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1539.htmlhttp://securitytracker.com/id/1032442https://camel.apache.org/security-advisories.data/CVE-2015-0264.txt.aschttps://git-wip-us.apache.org/repos/asf?p=camel.git%3Ba=commitdiff%3Bh=1df559649a96a1ca0368373387e542f46e4820dahttps://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3Ehttps://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3E
2015-06-03
Published