Apache Xalan Java XSLT library integer truncation issue when processing malicious XSLT stylesheets
High severity
GitHub Reviewed
Published
Jul 20, 2022
to the GitHub Advisory Database
•
Updated Jun 24, 2024
Description
Published by the National Vulnerability Database
Jul 19, 2022
Published to the GitHub Advisory Database
Jul 20, 2022
Reviewed
Jul 21, 2022
Last updated
Jun 24, 2024
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode.
A fix for this issue was published in September 2022 as part of an anticipated 2.7.3 release.
References