Skip to content

XXE in Apache Standard Taglibs

High severity GitHub Reviewed Published Sep 14, 2020 to the GitHub Advisory Database • Updated Feb 1, 2023

Package

maven org.apache.taglibs:taglibs-standard (Maven)

Affected versions

< 1.2.3

Patched versions

1.2.3
maven org.apache.taglibs:taglibs-standard-impl (Maven)
< 1.2.3
1.2.3

Description

Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.

References

Published by the National Vulnerability Database Mar 9, 2015
Reviewed Sep 14, 2020
Published to the GitHub Advisory Database Sep 14, 2020
Last updated Feb 1, 2023

Severity

High

EPSS score

7.089%
(94th percentile)

Weaknesses

CVE ID

CVE-2015-0254

GHSA ID

GHSA-6x4w-8w53-xrvv

Source code

No known source code
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.