BIT-java-min-2022-34169

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/java-min/BIT-java-min-2022-34169.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-java-min-2022-34169
Aliases
Published
2026-05-06T14:43:30.639Z
Modified
2026-05-08T07:56:11.683745630Z
Summary
Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets
Details

The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.

Database specific
{
    "severity": "High",
    "cpes": [
        "cpe:2.3:a:bellsoft:libericajdk:*:*:*:*:*:*:*:*"
    ]
}
References

Affected packages

Bitnami / java-min

Package

Name
java-min
Purl
pkg:bitnami/java-min

Severity

  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
1.8.0-333
Last affected
1.8.0-333
Introduced
11.0.15-1
Last affected
11.0.15-1
Introduced
17.0.3-1
Last affected
17.0.3-1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/java-min/BIT-java-min-2022-34169.json"