CVE-2015-0264: Medium severity red hat build of apache camel vulnerability
Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an invalid XML (1) String or (2) GenericFile object in an XPath query.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0264?
CVE-2015-0264 is classified as a medium severity vulnerability due to its potential to allow unauthorized file access.
How do I fix CVE-2015-0264?
To fix CVE-2015-0264, update Apache Camel to version 2.13.4 or 2.14.2 or later.
What are the affected versions for CVE-2015-0264?
Affected versions of Apache Camel include versions prior to 2.13.4 and 2.14.0 through 2.14.1.
What are the consequences of exploiting CVE-2015-0264?
Exploitation of CVE-2015-0264 allows attackers to read arbitrary files on the server by manipulating XML input.
Does CVE-2015-0264 affect all users of Apache Camel?
CVE-2015-0264 specifically affects users of Apache Camel versions 2.13.3 and below, and 2.14.0 and 2.14.1.