Skip to content

jstl-1.2.jar: 1 vulnerabilities (highest severity is: 7.3) [master] #68

Description

@renovate
📂 Vulnerable Library - jstl-1.2.jar

Path to dependency file: /pom.xml

Findings

Finding Severity 🎯 CVSS Exploit Maturity EPSS Library Type Fixed in Remediation Available Reachability
CVE-2015-0254 🔴 High 7.3 Not Defined 13.26% jstl-1.2.jar Direct org.apache.taglibs:taglibs-standard-impl:1.2.3

Details

🔴CVE-2015-0254

Vulnerable Library - jstl-1.2.jar

Library home page:

Path to dependency file: /pom.xml

Dependency Hierarchy:

  • jstl-1.2.jar (Vulnerable Library)

Vulnerability Details

Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.

Publish Date: Mar 09, 2015 02:00 PM

URL: CVE-2015-0254

Threat Assessment

Exploit Maturity:Not Defined

EPSS:13.26%

Score: 7.3


Suggested Fix

Type: Upgrade version

Origin: GHSA-6x4w-8w53-xrvv

Release Date: Mar 09, 2015 02:00 PM

Fix Resolution : org.apache.taglibs:taglibs-standard-impl:1.2.3

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions