GHSA-rc2w-r4jq-7pfx

Suggest an improvement
Source
https://github.com/advisories/GHSA-rc2w-r4jq-7pfx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rc2w-r4jq-7pfx/GHSA-rc2w-r4jq-7pfx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rc2w-r4jq-7pfx
Aliases
Published
2022-05-13T01:05:38Z
Modified
2024-12-05T05:43:33.818112Z
Summary
Improper Authorization in Apache Xalan-Java
Details

The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURESECUREPROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.

Database specific
{
    "nvd_published_at": "2014-04-15T23:13:00Z",
    "cwe_ids": [
        "CWE-285"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2022-07-07T23:02:09Z"
}
References

Affected packages

Maven / xalan:xalan

Package

Name
xalan:xalan
View open source insights on deps.dev
Purl
pkg:maven/xalan/xalan

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.2

Affected versions

2.*

2.1.0
2.3.1
2.4.0
2.4.1
2.5.0
2.5.D1
2.5.1
2.6.0
2.7.0
2.7.1