-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Labels
security vulnerabilitySecurity vulnerability detected by WhiteSourceSecurity vulnerability detected by WhiteSource
Description
CVE-2015-0254 - Medium Severity Vulnerability
Vulnerable Library - jstl-1.2.jar
Path to dependency file: JavaVulnerableLabImported/pom.xml
Path to vulnerable library: x/servlet/jstl/1.2/jstl-1.2.jar
Dependency Hierarchy:
- ❌ jstl-1.2.jar (Vulnerable Library)
Found in HEAD commit: 00a32086ab994407c873c91caa0a13eecdd1682e
Found in base branch: master
Vulnerability Details
Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.
Publish Date: 2015-03-09
URL: CVE-2015-0254
CVSS 3 Score Details (5.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: N/A
- Attack Complexity: N/A
- Privileges Required: N/A
- User Interaction: N/A
- Scope: N/A
- Impact Metrics:
- Confidentiality Impact: N/A
- Integrity Impact: N/A
- Availability Impact: N/A
Suggested Fix
Type: Upgrade version
Origin: https://tomcat.apache.org/taglibs/standard/
Release Date: 2015-03-09
Fix Resolution: org.apache.taglibs:taglibs-standard-impl:1.2.3
- Check this box to open an automated fix PR
Metadata
Metadata
Assignees
Labels
security vulnerabilitySecurity vulnerability detected by WhiteSourceSecurity vulnerability detected by WhiteSource