{"id":"GHSA-x6rc-54xp-ccxx","summary":"Withdrawn Advisory: Improper Restriction of XML External Entity Reference in Apache ActiveMQ","details":"## Withdrawn Advisory\nThis advisory has been withdrawn because further investgation revealed that this is not a security issue. This link is maintained to preserve external references.\n\n## Original Description\nXML external entity (XXE) vulnerability in the XPath selector component in Artemis ActiveMQ before commit 48d9951d879e0c8cbb59d4b64ab59d53ef88310d allows remote attackers to have unspecified impact via unknown vectors.","aliases":["CVE-2015-3208"],"modified":"2026-09-10T03:49:43.487718366Z","published":"2022-05-14T02:21:03Z","withdrawn":"2025-07-18T17:25:20Z","database_specific":{"github_reviewed_at":"2022-07-06T20:17:45Z","nvd_published_at":"2017-07-25T18:29:00Z","cwe_ids":["CWE-611"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-3208"},{"type":"WEB","url":"https://github.com/apache/activemq-artemis/commit/48d9951d879e0c8cbb59d4b64ab59d53ef88310d"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:2927"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1225252"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2015/07/24/2"}],"affected":[{"package":{"name":"org.apache.activemq:activemq-client","ecosystem":"Maven","purl":"pkg:maven/org.apache.activemq/activemq-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.23.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2.23.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-x6rc-54xp-ccxx/GHSA-x6rc-54xp-ccxx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}