CVE-2024-31573

EUVD-2024-1578
XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 12%
Debian logo
Debian Releases
Debian Product
Codename
xmlunit
bookworm
1.6-2
fixed
bullseye
1.6-2
fixed
forky
1.6-2
fixed
sid
1.6-2
fixed
trixie
1.6-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
xmlunit
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
plucky
needs-triage
questing
needs-triage
xenial
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
xmlunit
Amazon Linux 2023
0:2.8.2-6.amzn2023.0.4
fixed
xmlunit-assertj
Amazon Linux 2023
0:2.8.2-6.amzn2023.0.4
fixed
xmlunit-core
Amazon Linux 2023
0:2.8.2-6.amzn2023.0.4
fixed
xmlunit-javadoc
Amazon Linux 2023
0:2.8.2-6.amzn2023.0.4
fixed
xmlunit-legacy
Amazon Linux 2023
0:2.8.2-6.amzn2023.0.4
fixed
xmlunit-matchers
Amazon Linux 2023
0:2.8.2-6.amzn2023.0.4
fixed
xmlunit-placeholders
Amazon Linux 2023
0:2.8.2-6.amzn2023.0.4
fixed