CVE-2014-3600

CRITICAL9.8EPSS 0.51%

Improper Restriction of XML External Entity Reference in Apache ActiveMQ

發布日:2022/5/14修改日:2026/4/28

描述

XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1CRITICAL9.8CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

參考連結(9)