Vulnerable Library - jstl-1.2.jar
Path to dependency file: /pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/jstl/jstl/1.2/jstl-1.2.jar
Found in HEAD commit: f3f3628f646118a4ebab90d4fa130808243d0f42
Vulnerabilities
| CVE |
Severity |
CVSS |
Dependency |
Type |
Fixed in (jstl version) |
Remediation Possible** |
Reachability |
| CVE-2015-0254 |
High |
7.3 |
jstl-1.2.jar |
Direct |
org.apache.taglibs:taglibs-standard-impl:1.2.3 |
✅ |
|
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2015-0254
Vulnerable Library - jstl-1.2.jar
Path to dependency file: /pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/jstl/jstl/1.2/jstl-1.2.jar
Dependency Hierarchy:
- ❌ jstl-1.2.jar (Vulnerable Library)
Found in HEAD commit: f3f3628f646118a4ebab90d4fa130808243d0f42
Found in base branch: master
Vulnerability Details
Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.
Publish Date: 2015-03-09
URL: CVE-2015-0254
CVSS 3 Score Details (7.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: Low
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: https://tomcat.apache.org/taglibs/standard/
Release Date: 2015-03-09
Fix Resolution: org.apache.taglibs:taglibs-standard-impl:1.2.3
⛑️ Automatic Remediation will be attempted for this issue.
⛑️Automatic Remediation will be attempted for this issue.
Path to dependency file: /pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/jstl/jstl/1.2/jstl-1.2.jar
Found in HEAD commit: f3f3628f646118a4ebab90d4fa130808243d0f42
Vulnerabilities
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Vulnerable Library - jstl-1.2.jar
Path to dependency file: /pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/jstl/jstl/1.2/jstl-1.2.jar
Dependency Hierarchy:
Found in HEAD commit: f3f3628f646118a4ebab90d4fa130808243d0f42
Found in base branch: master
Vulnerability Details
Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.
Publish Date: 2015-03-09
URL: CVE-2015-0254
CVSS 3 Score Details (7.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: Low
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: https://tomcat.apache.org/taglibs/standard/
Release Date: 2015-03-09
Fix Resolution: org.apache.taglibs:taglibs-standard-impl:1.2.3
⛑️ Automatic Remediation will be attempted for this issue.
⛑️Automatic Remediation will be attempted for this issue.