Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9339-86wc-4qgf

Опубликовано: 20 июл. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Apache Xalan Java XSLT library integer truncation issue when processing malicious XSLT stylesheets

The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode.

A fix for this issue was published in September 2022 as part of an anticipated 2.7.3 release.

Ссылки

Пакеты

Наименование

xalan:xalan

maven
Затронутые версииВерсия исправления

< 2.7.3

2.7.3

EPSS

Процентиль: 93%
0.1173
Средний

7.5 High

CVSS3

Дефекты

CWE-681

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.

CVSS3: 7.5
redhat
почти 3 года назад

The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.

CVSS3: 7.5
nvd
почти 3 года назад

The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.

CVSS3: 7.5
debian
почти 3 года назад

The Apache Xalan Java XSLT library is vulnerable to an integer truncat ...

suse-cvrf
7 месяцев назад

Recommended update for mojo-parent

EPSS

Процентиль: 93%
0.1173
Средний

7.5 High

CVSS3

Дефекты

CWE-681