CVE-2015-0254
Publication date 9 March 2015
Last updated 24 July 2024
Ubuntu priority
Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.
Status
Package | Ubuntu Release | Status |
---|---|---|
jakarta-taglibs-standard | ||
16.04 LTS xenial |
Fixed 1.1.2-3ubuntu1
|
|
14.04 LTS trusty |
Fixed 1.1.2-2ubuntu1.14.04.1
|
|
References
Related Ubuntu Security Notices (USN)
- USN-2551-1
- Apache Standard Taglibs vulnerability
- 30 March 2015