Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.
| Software | From | Fixed in |
|---|---|---|
| apache / standard_taglibs | - | 1.2.1.x |
| canonical / ubuntu_linux | 14.10 | 14.10.x |
| canonical / ubuntu_linux | 14.04 | 14.04.x |
org.apache.taglibs / taglibs-standard
|
- | 1.2.3 |
org.apache.taglibs / taglibs-standard-impl
|
- | 1.2.3 |