{"id":"CVE-2014-0003","aliases":[],"url":"https://o3.security/vulnerability/CVE-2014-0003","summary":"Apache Camel's XSLT component allows remote attackers to execute arbitrary Java methods","details":"The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbitrary Java methods via a crafted message.","published":"2018-10-16T23:13:49Z","modified":"2024-12-06T05:31:17.748531Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.camel:camel-core","fixedVersion":"2.11.4"},{"ecosystem":"Maven","name":"org.apache.camel:camel-core","fixedVersion":"2.12.3"}],"fix":{"url":"https://github.com/apache/camel/commit/483b445dc77487e2d0f3d8c8bf1a7bbab04464c","label":"apache/camel@483b445"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-0003"},{"type":"WEB","url":"https://github.com/apache/camel/commit/483b445dc77487e2d0f3d8c8bf1a7bbab04464c"},{"type":"WEB","url":"https://github.com/apache/camel/commit/c6de749e9b3c7b61861c5480e91550290585224"},{"type":"WEB","url":"https://github.com/apache/camel/commit/e922f89290f236f3107039de61af0375826bd96d"},{"type":"PACKAGE","url":"https://github.com/apache/camel"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/CAMEL-7123"},{"type":"WEB","url":"https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf%40%3Ccommits.camel.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/2318d7f7d87724d8716cd650c21b31cb06e4d34f6d0f5ee42f28fdaf@%3Ccommits.camel.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d%40%3Ccommits.camel.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/b4014ea7c5830ca1fc28edd5cafedfe93ad4af2d9e69c961c5def31d@%3Ccommits.camel.apache.org%3E"},{"type":"WEB","url":"https://web.archive.org/web/20200229061309/http://www.securityfocus.com/bid/65902"},{"type":"WEB","url":"http://camel.apache.org/security-advisories.data/CVE-2014-0003.txt.asc"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-0245.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-0254.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-0371.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2014-0372.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-06T05:31:17.748531Z"}}