CVE-2019-11068

Modified
Published: 10 Apr 2019, 19:38
Last modified:28 May 2026, 18:18

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (nvd)
EPSS Score
1.13% LOW
1% probability +0.14%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

10 Apr 2019, 19:38
Published
Vulnerability first disclosed
28 May 2026, 18:18
Last Modified
Vulnerability information updated

Description

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 1.13% Percentile: 79%

Affected Systems

  • canonicalubuntu_linux

    12.04 | 14.04 | 16.04 | 18.04 | 18.10

  • debiandebian_linux

    8.0

  • fedoraprojectfedora

    29 | 30

  • netappactive_iq_unified_manager

    na

  • netappcloud_backup

    na

  • netappe-series_santricity_management_plug-ins

    na

  • netappe-series_santricity_os_controller

    ≥ 11.0, ≤ 11.70.2

  • netappe-series_santricity_storage_manager

    na

  • netappe-series_santricity_unified_manager

    na

  • netappe-series_santricity_web_services_proxy

    na

  • netappelement_software

    na

  • netapphci_management_node

    na

  • netapponcommand_insight

    na

  • netapponcommand_workflow_automation

    na

  • netappplug-in_for_symantec_netbackup

    na

  • netappsantricity_unified_manager

    na

  • netappsnapmanager

    na

  • netappsolidfire

    na

  • netappsteelstore_cloud_integrated_storage

    na

  • opensuseleap

    15.0 | 15.1 | 42.3

  • oraclejdk

    8.0:update_221

  • xmlsoftlibxslt

    ≤ 1.1.33

References (16)