Lucene search

K
osvGoogleOSV:GHSA-6X4W-8W53-XRVV
HistorySep 14, 2020 - 6:44 p.m.

XXE in Apache Standard Taglibs

2020-09-1418:44:01
Google
osv.dev
28
apache taglibs
remote code execution
xml entity attack

EPSS

0.071

Percentile

94.1%

Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.

References