Description
XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
Remediation
References
http://activemq.apache.org/security-advisories.data/CVE-2014-3579-announcement.txt
http://seclists.org/oss-sec/2015/q1/428
http://www.securityfocus.com/bid/72508
https://exchange.xforce.ibmcloud.com/vulnerabilities/100721
https://issues.apache.org/jira/browse/APLO-366
https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E
Related Vulnerabilities
CVE-2023-22832 Vulnerability in maven package org.apache.nifi:nifi-ccda-processors
CVE-2022-34115 Vulnerability in maven package io.dataease:dataease-plugin-common
CVE-2020-14340 Vulnerability in maven package org.jboss.xnio:xnio-nio
CVE-2021-43138 Vulnerability in maven package org.webjars.npm:async
CVE-2023-43497 Vulnerability in maven package org.jenkins-ci.main:jenkins-core