Updated jakarta-taglibs-standard packages fix security vulnerability:
David Jorm discovered that the Apache Standard Taglibs incorrectly handled external XML entities. A remote attacker could possibly use this issue to execute arbitrary code or perform other external XML entity attacks (CVE-2015-0254).