Xalan-J XSLTC Integer Truncation
Posted by deepcore on August 26, 2022 – 11:56 pm
The Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode.
Post a reply
You must be logged in to post a comment.