QID 981996

QID 981996: Java (maven) Security Update for org.apache.taglibs:taglibs-standard-impl (GHSA-6x4w-8w53-xrvv)

Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 4.2 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer to GHSA-6x4w-8w53-xrvv for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981996

    Software Advisories
    Advisory ID Software Component Link
    GHSA-6x4w-8w53-xrvv org.apache.taglibs:taglibs-standard URL Logo github.com/advisories/GHSA-6x4w-8w53-xrvv
    GHSA-6x4w-8w53-xrvv org.apache.taglibs:taglibs-standard-impl URL Logo github.com/advisories/GHSA-6x4w-8w53-xrvv