VDB
BIT-java-2022-34169
BIT-java-2022-34169
PUBLISHED
CVSS 7.5 HIGH
Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets
Risk Scores
CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | java | 1.8.0-333, 11.0.15-1, 17.0.3-1 |
Timeline
- May 6, 2026 CVE Published
- May 7, 2026 Distribution Patch
- May 7, 2026 Distribution Patch
- May 7, 2026 Distribution Patch
- May 8, 2026 CVE Updated
References
- http://packetstormsecurity.com/files/168186/Xalan-J-XSLTC-Integer-Truncation.html url
- http://www.openwall.com/lists/oss-security/2022/07/19/5 url
- http://www.openwall.com/lists/oss-security/2022/07/19/6 url
- http://www.openwall.com/lists/oss-security/2022/07/20/2 url
- http://www.openwall.com/lists/oss-security/2022/07/20/3 url
- http://www.openwall.com/lists/oss-security/2022/10/18/2 url
- http://www.openwall.com/lists/oss-security/2022/11/04/8 url
- http://www.openwall.com/lists/oss-security/2022/11/07/2 url
- https://lists.apache.org/thread/12pxy4phsry6c34x2ol4fft6xlho4kyw url
- https://lists.apache.org/thread/2qvl7r43wb4t8p9dd9om1bnkssk07sn8 url
- https://lists.debian.org/debian-lts-announce/2022/10/msg00024.html url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H4YNJSJ64NPCNKFPNBYITNZU5H3L4D6L/ url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I5OZNAZJ4YHLOKRRRZSWRT5OJ25E4XLM/ url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JN3EVGR7FD3ZLV5SBTJXUIDCMSK4QUE2/ url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KO3DXNKZ4EU3UZBT6AAR4XRKCD73KLMO/ url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L3XPOTPPBZIPFBZHQE5E7OW6PDACUMCJ/ url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YULPNO3PAWMEQQZV2C54I3H3ZOXFZUTB/ url
- https://nvd.nist.gov/vuln/detail/CVE-2022-34169 url
- https://security.gentoo.org/glsa/202401-25 url
- https://security.netapp.com/advisory/ntap-20220729-0009/ url
…and 5 more