MEDIUM 4.0 Microsoft
CVE-2024-31573
XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.
Microsoft Security Update 2025-Oct: XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.
Affected Products
- cbl2 javapackages-bootstrap 1.5.0-7 on CBL Mariner 2.0
- azl3 javapackages-bootstrap 1.14.0-3 on Azure Linux 3.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-31573
- https://nvd.nist.gov/vuln/detail/CVE-2024-31573
This medium severity vulnerability with a CVSS score of 4.0 was published on 2025-10-14 via Microsoft. Affected: cbl2 javapackages-bootstrap 1.5.0-7 on CBL Mariner 2.0, azl3 javapackages-bootstrap 1.14.0-3 on Azure Linux 3.0.
vulnfeed aggregates 8893 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.