CVE-2014-0030: XEE
Published Oct 9, 2017
·Updated
The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
Affected Software
6 affected components
Apache Roller=3.1
Apache Roller=4.0
Apache Roller=4.0.1
Apache Roller=5.0
Apache Roller=5.0.1
Apache Roller=5.0.2
Event History
Oct 9, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-0030?
CVE-2014-0030 is classified as a medium severity vulnerability due to its potential for XML External Entity (XXE) attacks.
2
How do I fix CVE-2014-0030?
To fix CVE-2014-0030, you should upgrade to Apache Roller version 5.0.3 or later, which addresses the vulnerability.
3
What does CVE-2014-0030 exploit?
CVE-2014-0030 exploits vulnerabilities in the XML-RPC protocol support of Apache Roller, allowing for potential XXE attacks.
4
Which versions of Apache Roller are affected by CVE-2014-0030?
Apache Roller versions 3.1, 4.0, 4.0.1, 5.0, 5.0.1, and 5.0.2 are all affected by CVE-2014-0030.
5
What type of attacks can be conducted using CVE-2014-0030?
CVE-2014-0030 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.