ZeroHour

CVE-2024-31573

CVSS 3.1
4.0 medium
EPSS
<1%p13
Published
()
Modified
Description

XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.

Weakness
CWE-669
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.