CVE-2015-0263
EUVD-2018-048703.06.2015, 20:59
XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attackers to read arbitrary files via an external entity in an SAXSource.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | camel | 𝑥 ≤ 2.13.3 |
| apache | camel | 2.14.0 |
| apache | camel | 2.14.1 |
𝑥
= Vulnerable software versions
References