CVE Vulnerabilities

CVE-2014-3629

Published: Nov 17, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
3.5 LOW
AV:N/AC:M/Au:S/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

XML external entity (XXE) vulnerability in the XML Exchange module in Apache Qpid 0.30 allows remote attackers to cause outgoing HTTP connections via a crafted message.

Affected Software

NameVendorStart VersionEnd Version
QpidApache0.30 (including)0.30 (including)
Qpid-cppUbuntuartful*
Qpid-cppUbuntuesm-apps/xenial*
Qpid-cppUbuntuprecise*
Qpid-cppUbuntutrusty*
Qpid-cppUbuntuutopic*
Qpid-cppUbuntuvivid*
Qpid-cppUbuntuwily*
Qpid-cppUbuntuxenial*
Qpid-cppUbuntuyakkety*
Qpid-cppUbuntuzesty*

References