GHSA-rc2w-r4jq-7pfx

Suggest an improvement
Source
https://github.com/advisories/GHSA-rc2w-r4jq-7pfx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rc2w-r4jq-7pfx/GHSA-rc2w-r4jq-7pfx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rc2w-r4jq-7pfx
Aliases
Published
2022-05-13T01:05:38Z
Modified
2025-04-13T23:37:05Z
Summary
Improper Authorization in Apache Xalan-Java
Details

The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.

Database specific
{
    "cwe_ids":  [
        "CWE-285"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2022-07-07T23:02:09Z",
    "nvd_published_at":  "2014-04-15T23:13:00Z",
    "severity":  "HIGH"
}
References

Affected packages

Maven / xalan:xalan

Package

Name
xalan:xalan
View open source insights on deps.dev
Purl
pkg:maven/xalan/xalan

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.7.2

Affected versions

2.*
2.1.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.D1
2.5.1
2.6.0
2.7.0
2.7.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rc2w-r4jq-7pfx/GHSA-rc2w-r4jq-7pfx.json"