Security Advisory

CVE-2019-11068

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-04-10 19:38:18
Last updated 2026-05-28 18:18:27
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.