MEDIUM 4.0 Microsoft

CVE-2024-31573

XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.

Microsoft Security Update 2025-Oct: XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension functions are enabled.

Affected Products

References

Published: 2025-10-14 · Source: Microsoft · Feed updated: 2026-08-10
This medium severity vulnerability with a CVSS score of 4.0 was published on 2025-10-14 via Microsoft. Affected: cbl2 javapackages-bootstrap 1.5.0-7 on CBL Mariner 2.0, azl3 javapackages-bootstrap 1.14.0-3 on Azure Linux 3.0.
vulnfeed aggregates 8893 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.