XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.
Metrics
Affected Vendors & Products
References
History
Sat, 18 Oct 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | org.xmlunit/xmlunit-core: XMLUnit Insecure Defaults when Processing XSLT Stylesheets | |
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Fri, 17 Oct 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 17 Oct 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-669 | |
Metrics |
cvssV3_1
|
Fri, 17 Oct 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-17T19:04:05.637Z
Reserved: 2024-04-05T00:00:00.000Z
Link: CVE-2024-31573

Updated: 2025-10-17T19:03:52.228Z

Status : Received
Published: 2025-10-17T19:15:36.627
Modified: 2025-10-17T19:15:36.627
Link: CVE-2024-31573


No data.