XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.
Metrics
Affected Vendors & Products
References
History
Thu, 23 Oct 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xmlunit
Xmlunit xmlunit |
|
| Vendors & Products |
Xmlunit
Xmlunit xmlunit |
Sat, 18 Oct 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | org.xmlunit/xmlunit-core: XMLUnit Insecure Defaults when Processing XSLT Stylesheets | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 17 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Oct 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-669 | |
| Metrics |
cvssV3_1
|
Fri, 17 Oct 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-17T19:04:05.637Z
Reserved: 2024-04-05T00:00:00.000Z
Link: CVE-2024-31573
Updated: 2025-10-17T19:03:52.228Z
Status : Awaiting Analysis
Published: 2025-10-17T19:15:36.627
Modified: 2025-10-21T19:31:50.020
Link: CVE-2024-31573