Description
XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
Remediation
References
https://issues.apache.org/jira/browse/APLO-366
https://exchange.xforce.ibmcloud.com/vulnerabilities/100721
http://www.securityfocus.com/bid/72508
http://seclists.org/oss-sec/2015/q1/428
http://activemq.apache.org/security-advisories.data/CVE-2014-3579-announcement.txt
https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E
Related Vulnerabilities
CVE-2023-38690 Vulnerability in npm package matrix-appservice-irc
CVE-2014-3607 Vulnerability in maven package org.ldaptive:ldaptive
CVE-2020-16022 Vulnerability in maven package org.webjars.npm:electron
CVE-2019-16776 Vulnerability in maven package org.webjars.npm:bin-links
CVE-2022-31147 Vulnerability in npm package jquery-validation