Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) or (2) JSTL XML tag.
Loading...
Loading...
Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) or (2) JSTL XML tag.
March 9, 2015
May 6, 2026
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| ubuntu | libjstl1.1-java (1.1.2-2ubuntu1.14.10.1) @ utopic | 2026-05-28 | ubuntu |
| redhat | eap7-xml-security-0:2.0.6-1.redhat_1.1.ep7.el6 | 2016-09-08 | redhat |
| redhat | eap7-xml-security-0:2.0.6-1.redhat_1.1.ep7.el7 | 2016-09-08 | redhat |
| redhat | patch | 2016-09-08 | redhat |
| redhat | eap7-jboss-ec2-eap-0:7.0.2-2.GA_redhat_1.ep7.el7 | 2016-09-08 | redhat |
| redhat | web | 2016-06-30 | redhat |
| redhat | xml-security-0:1.5.8-1.redhat_1.1.ep6.el7 | 2016-02-04 | redhat |
| redhat | patch | 2016-02-04 | redhat |
| redhat | xml-security-0:1.5.8-1.redhat_1.1.ep6.el5 | 2016-02-04 | redhat |
| redhat | xml-security-0:1.5.8-1.redhat_1.1.ep6.el6 | 2016-02-04 | redhat |
| redhat | jboss-ec2-eap-0:7.5.6-1.Final_redhat_1.ep6.el6 | 2016-02-04 | redhat |
| redhat | jakarta-taglibs-standard-0:1.1.2-14.ael7b_1 | 2015-08-31 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| org.apache.taglibs:taglibs-standard | 1.2.1 | 1.2.3 | — |
| org.apache.taglibs:taglibs-standard-impl | 1.2.1 | 1.2.3 | — |
Every vendor that published an advisory referencing this CVE — pulled from our cve_vendor_advisories aggregation. Click any row for the vendor's original advisory page.
RHSA-2015:1695 — Important
RHSA-2016:0121 — Important
RHSA-2016:0122 — Important
RHSA-2016:0123 — Important
RHSA-2016:0124 — Important
RHSA-2016:0125 — Important
RHSA-2016:1376 — Important
RHSA-2016:1838 — Important
RHSA-2016:1839 — Important
RHSA-2016:1840 — Important
RHSA-2016:1841 — Important
Apache Standard Taglibs vulnerability
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2015-0254
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.