BIT-jre-2022-34169

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/jre/BIT-jre-2022-34169.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-jre-2022-34169
Aliases
Published
2026-05-08T05:44:59Z
Modified
2026-09-08T08:47:29Z
Summary
Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets
Details

The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are recommended to update to version 2.7.3 or later. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.

Database specific
{
    "cpes": [
        "cpe:2.3:a:bellsoft:libericajre:*:*:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / jre

Package

Name
jre
Purl
pkg:bitnami/jre

Severity

  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
1.8.0-333
Last Affected
1.8.0-333
Introduced
11.0.15-1
Last Affected
11.0.15-1
Introduced
17.0.3-1
Last Affected
17.0.3-1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/jre/BIT-jre-2022-34169.json"