Description
XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.
Problem types
CWE-669 Incorrect Resource Transfer Between Spheres
Product status
2.0.0 before 2.10.0
References
github.com/advisories/GHSA-chfm-68vv-pvw5
github.com/xmlunit/xmlunit/issues/264
github.com/...ommit/b81d48b71dfd2868bdfc30a3e17ff973f32bc15b