CVE ID(s)
There's no CVE for this.
Report
I created a query to detect XSLT injections in Java code. The query raises a flag if user-provided XSLT stylesheet is processed. StreamSource, SAXSource, StAXSource and DOMSource are supported as well as creating the Transformer via Templates.
XSLT injection can lead to RCE.
The details are present in PR: github/codeql#3363
CVE ID(s)
There's no CVE for this.
Report
I created a query to detect XSLT injections in Java code. The query raises a flag if user-provided XSLT stylesheet is processed.
StreamSource,SAXSource,StAXSourceandDOMSourceare supported as well as creating theTransformerviaTemplates.XSLT injection can lead to RCE.
The details are present in PR: github/codeql#3363