Home
MEDIUM: 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:NDefault status
unknown
2.0.0 (semver) before 2.10.0
affected
Description
XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.
Problem types
CWE-669 Incorrect Resource Transfer Between Spheres
Product status
2.0.0 (semver) before 2.10.0
References
github.com/xmlunit/xmlunit/issues/264
github.com/advisories/GHSA-chfm-68vv-pvw5
github.com/xmlunit/xmlunit/issues/264
github.com/...ommit/b81d48b71dfd2868bdfc30a3e17ff973f32bc15b