CVE-2014-3004 describes an XML External Entity (XXE) vulnerability in the default configuration of the Xerces SAX Parser within Castor versions prior to 1.3.3, affecting Castor and OpenSUSE products. This medium-complexity vulnerability (CVSS 4.3) allows unauthenticated attackers to disclose sensitive information via specially crafted XML documents. While not actively exploited in the wild and not on the KEV catalog, a public exploit (EDB-39205) exists, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.3.2CPE matchmatch criteria | cpe:2.3:a:castor_project:castor:*:*:*:*:*:*:*:* | ||
1.3CPE matchmatch criteria | cpe:2.3:a:castor_project:castor:1.3:*:*:*:*:*:*:* | ||
1.3.1CPE matchmatch criteria | cpe:2.3:a:castor_project:castor:1.3.1:*:*:*:*:*:*:* | ||
13.1CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:* | ||
12.3CPE matchmatch criteria | cpe:2.3:o:opensuse_project:opensuse:12.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.