CVE-2024-36522
CVE-2024-36522 is a critical remote code execution vulnerability affecting XSLTResourceStream.java due to improper handling of untrusted input. This XSLT injection flaw allows attackers to execute arbitrary code when processing data without adequate validation. Although the SVRS is 30, indicating a lower immediate risk compared to critical vulnerabilities, the presence of the "In The Wild" tag suggests active exploitation. Users should immediately upgrade to versions 10.1.0, 9.18.0, or 8.16.0 to mitigate this risk. Failure to update could result in compromised systems and data breaches. This vulnerability is significant because it highlights the danger of processing untrusted input without proper sanitization, a common weakness exploited by attackers. The vendor advisory emphasizes the importance of applying the provided patch.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.