-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| xalan:xalan | maven | < 2.7.3 | 2.7.3 |
The key vulnerability manifests in XSLTC's class generation process. The dumpClass method was modified to add bytecode validation through a custom classloader, indicating it was previously writing potentially corrupted classes. The ErrorMsg changes show improved error reporting for class verification failures, which would occur when exploiting the integer truncation issue. These functions are directly involved in the class file generation and error handling pipeline where numeric conversion vulnerabilities would surface during malicious XSLT processing.
Ongoing coverage of React2Shell