Lucene search

K
githubGitHub Advisory DatabaseGHSA-6X4W-8W53-XRVV
HistorySep 14, 2020 - 6:44 p.m.

XXE in Apache Standard Taglibs

2020-09-1418:44:01
CWE-611
GitHub Advisory Database
github.com
30
apache standard taglibs
xxe
remote code execution
xml entity attacks
xslt extension
jstl xml tag

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.071

Percentile

94.1%

Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.

Affected configurations

Vulners
Node
org.apache.taglibstaglibs-standard-implRange<1.2.3
OR
org.apache.taglibstaglibs-standardRange<1.2.3
VendorProductVersionCPE
org.apache.taglibstaglibs-standard-impl*cpe:2.3:a:org.apache.taglibs:taglibs-standard-impl:*:*:*:*:*:*:*:*
org.apache.taglibstaglibs-standard*cpe:2.3:a:org.apache.taglibs:taglibs-standard:*:*:*:*:*:*:*:*

References

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.071

Percentile

94.1%