[ANNOUNCE] CVE-2014-0002 and CVE-2014-0003 - Apache Camel critical disclosure vulnerability

Christian Mueller <[email protected]>
Newsgroups gmane.comp.apache.maven.announce,gmane.comp.security.full-disclosure,gmane.comp.apache.incubator.bigtop.devel,gmane.comp.jakarta.tomcat.user,gmane.comp.security.bugtraq
Message-ID <CALvzYd-mcX-YJsP1N3wK7wWkgGg_i_5+-wMq==NU2OMK7yKcvA__16460.9078238302$1393675730$gmane$org@mail.gmail.com>
If you are using the Apache Camel XSLT component, please note that the
security advisories CVE-2014-0002 and CVE-2014-0003 may affect you.

Please study these critical security vulnerability carefully!

http://camel.apache.org/security-advisories.data/CVE-2014-0002.txt.asc
http://camel.apache.org/security-advisories.data/CVE-2014-0003.txt.asc

You can download the fixed Apache Camel 2.11.x and 2.12.x version from the
Apache mirrors or from the Central Maven repository.

[1] http://camel.apache.org/xslt
[2] http://camel.apache.org/download

On behalf of the Camel PMC,
Christian

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.