CVE-2024-31573
—CVSS 3.1
4.0 medium
EPSS
<1%p13
Published
()
Modified
Description
XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.
- Weakness
- CWE-669
- Vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.