forked from in28minutes/JavaWebApplicationStepByStep
-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Labels
Mend: dependency security vulnerabilitySecurity vulnerability detected by MendSecurity vulnerability detected by Mend
Description
CVE-2015-0254 - High Severity Vulnerability
Vulnerable Library - jstl-1.2.jar
Path to dependency file: /pom.xml
Path to vulnerable library: /ervlet/jstl/1.2/jstl-1.2.jar,/target/in28Minutes-first-webapp-0.0.1-SNAPSHOT/WEB-INF/lib/jstl-1.2.jar
Dependency Hierarchy:
- ❌ jstl-1.2.jar (Vulnerable Library)
Found in base branch: master
Vulnerability Details
Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.
Publish Date: 2015-03-09
URL: CVE-2015-0254
CVSS 3 Score Details (7.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: Low
Suggested Fix
Type: Upgrade version
Origin: GHSA-6x4w-8w53-xrvv
Release Date: 2015-03-09
Fix Resolution: org.apache.taglibs:taglibs-standard-impl:1.2.3
Step up your Open Source Security Game with Mend here
Metadata
Metadata
Assignees
Labels
Mend: dependency security vulnerabilitySecurity vulnerability detected by MendSecurity vulnerability detected by Mend