XML external entity (XXE) vulnerability in the XPath selector component in Artemis ActiveMQ before commit 48d9951d879e0c8cbb59d4b64ab59d53ef88310d allows remote attackers to have unspecified impact via unknown vectors.
References
| Link | Resource |
|---|---|
| https://github.com/apache/activemq-artemis/commit/48d9951d879e0c8cbb59d4b64ab59d53ef88310d | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=1225252 | Issue Tracking Patch Third Party Advisory VDB Entry |
| http://www.securityfocus.com/bid/76025 | Third Party Advisory VDB Entry |
| http://www.openwall.com/lists/oss-security/2015/07/24/2 | Mailing List Patch VDB Entry |
| https://access.redhat.com/errata/RHSA-2018:2927 |
Configurations
Information
Published : 2017-07-25 18:29
Updated : 2018-10-17 10:29
NVD link : CVE-2015-3208
Mitre link : CVE-2015-3208
JSON object : View
Products Affected
apache
- activemq_artemis
CWE
CWE-611
Improper Restriction of XML External Entity Reference
