XXE in Apache Standard Taglibs
High severity
GitHub Reviewed
Published
Sep 14, 2020
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Mar 9, 2015
Reviewed
Sep 14, 2020
Published to the GitHub Advisory Database
Sep 14, 2020
Last updated
Feb 1, 2023
Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.
References