XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.
Metrics
Affected Vendors & Products
References
History
Thu, 23 Oct 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Xmlunit
Xmlunit xmlunit |
|
Vendors & Products |
Xmlunit
Xmlunit xmlunit |
Sat, 18 Oct 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | org.xmlunit/xmlunit-core: XMLUnit Insecure Defaults when Processing XSLT Stylesheets | |
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Fri, 17 Oct 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 17 Oct 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-669 | |
Metrics |
cvssV3_1
|
Fri, 17 Oct 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-10-17T00:00:00.000Z
Updated: 2025-10-17T19:04:05.637Z
Reserved: 2024-04-05T00:00:00.000Z
Link: CVE-2024-31573

Updated: 2025-10-17T19:03:52.228Z

Status : Awaiting Analysis
Published: 2025-10-17T19:15:36.627
Modified: 2025-10-21T19:31:50.020
Link: CVE-2024-31573
