logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2022-34169

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2022-34169

Description:
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.
Last updated date:
06/21/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
01/17/2023
Reference url to background

https://github.com/flowerwind/AutoGenerateXalanPayload

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2025

Privacy Policy