Description
XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
Remediation
References
http://activemq.apache.org/security-advisories.data/CVE-2014-3579-announcement.txt
http://seclists.org/oss-sec/2015/q1/428
http://www.securityfocus.com/bid/72508
https://exchange.xforce.ibmcloud.com/vulnerabilities/100721
https://issues.apache.org/jira/browse/APLO-366
https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E
Related Vulnerabilities
CVE-2018-6874 Vulnerability in maven package org.webjars.npm:auth0-lock
CVE-2019-10425 Vulnerability in maven package org.jvnet.hudson.plugins:gcal
CVE-2021-26073 Vulnerability in npm package atlassian-connect-express
CVE-2021-4178 Vulnerability in maven package io.fabric8:kubernetes-client
CVE-2022-43426 Vulnerability in maven package io.jenkins.plugins:s3explorer