CVE-2014-3004

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
11/06/2014
Last modified:
12/04/2025

Description

The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:castor_project:castor:*:*:*:*:*:*:*:* 1.3.2 (including)
cpe:2.3:a:castor_project:castor:1.3:*:*:*:*:*:*:*
cpe:2.3:a:castor_project:castor:1.3.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse_project:opensuse:12.3:*:*:*:*:*:*:*