icon

We found results for “

CVE-2015-0254

Date: March 9, 2015

Overview

XXE vulnerability affecting Apache Standard Taglibs before 1.2.3

Details

Apache Standard Taglibs is a popular open-source repository for JSP (JavaServer Pages) custom tag libraries and related projects. It’s an implementation of the JSP Standard Tag Library (JSTL) specification, which supports common structural tasks, such as conditional execution and XML data processing. Its affected versions allow an attacker to execute arbitrary code or carry out XML external entities (XXE) attacks.

Affected Environments

Apache Standard Taglibs versions before 1.2.3

Prevention

Update to Apache Standard Taglibs 1.2.3 or higher

Language: Java

Good to know:

icon
icon

Improper Restriction of XML External Entity Reference ('XXE')

CWE-611
icon

Upgrade Version

Upgrade to version 1.2.3

Learn More

Base Score:
Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope (S): Unchanged
Confidentiality (C): Low
Integrity (I): Low
Availability (A): Low
Base Score:
Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (AU): None
Confidentiality (C): Partial
Integrity (I): Partial
Availability (A): Partial
Additional information:

Related Resources (33)