📂 Vulnerable Library - jstl-1.2.jar
Path to dependency file: /pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/javax/servlet/jstl/1.2/jstl-1.2.jar
Findings
| Finding |
Severity |
🎯 CVSS |
Exploit Maturity |
EPSS |
Library |
Type |
Fixed in |
Remediation Available |
Reachability |
| CVE-2015-0254 |
🟠 Medium |
6.9 |
Not Defined |
3.8% |
jstl-1.2.jar |
Direct |
org.apache.taglibs:taglibs-standard-impl:1.2.3 |
✅ |
Unreachable |
Details
🟠CVE-2015-0254
Vulnerable Library - jstl-1.2.jar
Library home page:
Path to dependency file: /pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/javax/servlet/jstl/1.2/jstl-1.2.jar
Dependency Hierarchy:
- ❌ jstl-1.2.jar (Vulnerable Library)
Reachability Analysis
The vulnerable code is unreachable
Vulnerability Details
Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.
Publish Date: Mar 09, 2015 02:00 PM
URL: CVE-2015-0254
Threat Assessment
Exploit Maturity:Not Defined
EPSS:3.8%
Score: 6.9
Suggested Fix
Type: Upgrade version
Origin: GHSA-6x4w-8w53-xrvv
Release Date: Mar 09, 2015 02:00 PM
Fix Resolution : org.apache.taglibs:taglibs-standard-impl:1.2.3
📂 Vulnerable Library - jstl-1.2.jar
Path to dependency file: /pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/javax/servlet/jstl/1.2/jstl-1.2.jar
Findings
Details
🟠CVE-2015-0254
Vulnerable Library - jstl-1.2.jar
Library home page:
Path to dependency file: /pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/javax/servlet/jstl/1.2/jstl-1.2.jar
Dependency Hierarchy:
Reachability Analysis
The vulnerable code is unreachable
Vulnerability Details
Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.
Publish Date: Mar 09, 2015 02:00 PM
URL: CVE-2015-0254
Threat Assessment
Exploit Maturity:Not Defined
EPSS:3.8%
Score: 6.9
Suggested Fix
Type: Upgrade version
Origin: GHSA-6x4w-8w53-xrvv
Release Date: Mar 09, 2015 02:00 PM
Fix Resolution : org.apache.taglibs:taglibs-standard-impl:1.2.3