Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.apache.taglibs:taglibs-standard(Maven) | 0 | 1.2.3 | N/A |
| org.apache.taglibs:taglibs-standard-impl(Maven) | 0 | 1.2.3 | N/A |
CVSS Metrics