CVE-2014-0002
high
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
7.5
Description
Apache Camel's XSLT component allows remote attackers to read arbitrary files
Predictions
Exploit likelihood
20%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | org.apache.camel:camel-core | <2.11.4 | 2.11.4 |
| Maven | org.apache.camel:camel-core | >=2.12.0,<2.12.3 | 2.12.3 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| apache | camel | {"endIncluding":"2.11.3"} | |
| apache | camel | 1.0.0 | |
| apache | camel | 1.1.0 | |
| apache | camel | 1.2.0 | |
| apache | camel | 1.3.0 | |
| apache | camel | 1.4.0 | |
| apache | camel | 1.5.0 | |
| apache | camel | 1.6.0 | |
| apache | camel | 1.6.1 | |
| apache | camel | 1.6.2 | |
| apache | camel | 1.6.3 | |
| apache | camel | 1.6.4 | |
| apache | camel | 2.0.0 | |
| apache | camel | 2.1.0 | |
| apache | camel | 2.10.0 | |
| apache | camel | 2.10.1 | |
| apache | camel | 2.10.2 | |
| apache | camel | 2.10.3 | |
| apache | camel | 2.10.4 | |
| apache | camel | 2.10.5 | |
| apache | camel | 2.10.6 | |
| apache | camel | 2.10.7 | |
| apache | camel | 2.11.0 | |
| apache | camel | 2.11.1 | |
| apache | camel | 2.11.2 | |
| apache | camel | 2.12.0 | |
| apache | camel | 2.12.1 | |
| apache | camel | 2.12.2 | |
References
- http://camel.apache.org/security-advisories.data/CVE-2014-0002.txt.asc
- http://rhn.redhat.com/errata/RHSA-2014-0371.html
- http://rhn.redhat.com/errata/RHSA-2014-0372.html
- http://secunia.com/advisories/57125
- http://secunia.com/advisories/57716
- http://secunia.com/advisories/57719
- http://www.securityfocus.com/bid/65901
- https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3E
- https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2014-0002
- https://github.com/apache/camel/commit/2ec54fa0c13ae65bdcccff764af081a79fcc05f
- https://github.com/apache/camel/commit/341d4e6cca71c53c90962d1c3d45fc9e05cc50c6
- https://github.com/apache/camel/commit/54b65c1d30848835f26bd138c0ba407bc1e560d
- https://github.com/apache/camel
- https://issues.apache.org/jira/browse/CAMEL-7129
- https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf@%3Ccommits.camel.apache.org%3E
- https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d@%3Ccommits.camel.apache.org%3E
- https://web.archive.org/web/20200229061309/http://www.securityfocus.com/bid/65901
CWEs
CWE-264
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.