We found results for “”
CVE-2015-0254
Date: March 9, 2015
Overview
XXE vulnerability affecting Apache Standard Taglibs before 1.2.3Details
Apache Standard Taglibs is a popular open-source repository for JSP (JavaServer Pages) custom tag libraries and related projects. It’s an implementation of the JSP Standard Tag Library (JSTL) specification, which supports common structural tasks, such as conditional execution and XML data processing. Its affected versions allow an attacker to execute arbitrary code or carry out XML external entities (XXE) attacks.Affected Environments
Apache Standard Taglibs versions before 1.2.3Prevention
Update to Apache Standard Taglibs 1.2.3 or higherLanguage: Java
Good to know:
Base Score: |
|
---|---|
Attack Vector (AV): | Network |
Attack Complexity (AC): | Low |
Privileges Required (PR): | None |
User Interaction (UI): | None |
Scope (S): | Unchanged |
Confidentiality (C): | Low |
Integrity (I): | Low |
Availability (A): | Low |
Base Score: |
|
---|---|
Access Vector (AV): | Network |
Access Complexity (AC): | Low |
Authentication (AU): | None |
Confidentiality (C): | Partial |
Integrity (I): | Partial |
Availability (A): | Partial |
Additional information: |