VYPR

Maven package

org.esigate/esigate-core

pkg:maven/org.esigate/esigate-core

Vulnerabilities (1)

  • CVE-2018-1000854Dec 20, 2018
    affected < 5.3fixed 5.3

    esigate.org esigate version 5.2 and earlier contains a CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in ESI directive with user specified XSLT that can result in Remote Code Execution. This attack appear t