CVE-2014-3629 is an XML external entity (XXE) vulnerability in the XML Exchange module of Apache Qpid 0.30. This flaw allows remote attackers to initiate outgoing HTTP connections through a specially crafted message. With a CVSS score of 4.3, it is a medium-severity vulnerability, requiring moderate attack complexity and primarily impacting confidentiality by potentially disclosing local files or network information. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or Nuclei, and it has received limited community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.30CPE matchmatch criteria | cpe:2.3:a:apache:qpid:0.30:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.