Description
XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
Remediation
References
http://activemq.apache.org/security-advisories.data/CVE-2014-3579-announcement.txt
http://seclists.org/oss-sec/2015/q1/428
http://www.securityfocus.com/bid/72508
https://exchange.xforce.ibmcloud.com/vulnerabilities/100721
https://issues.apache.org/jira/browse/APLO-366
https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E
Related Vulnerabilities
CVE-2021-21160 Vulnerability in npm package electron
CVE-2018-11804 Vulnerability in maven package org.apache.spark:spark-core
CVE-2023-36470 Vulnerability in maven package org.xwiki.platform:xwiki-platform-icon-default
CVE-2016-1000220 Vulnerability in npm package kibana
CVE-2022-46907 Vulnerability in maven package org.apache.jspwiki:jspwiki-war