
SGaurav140689 (Community Member) asked a question.
CVE-2015-0254 for jstl-1.1.2. How do I get rid of this high vulnerability if there is no version of this jar which is not vulnerable. During my research I found that apache-standard-taglibs library is a good way to remediate this. But my problem here is: My application is in development phase and we don't know which application server the application will end up on( Jboss or WAS). So, Is apache-standard-taglibs compatible with both jboss and WAS ?
The jars available in my artifactory are below. If I replace jstl-1.1.2 with below dependencies, will the application work?
<!-- https://mvnrepository.com/artifact/org.apache.taglibs/taglibs-standard-spec -->
<dependency>
<groupId>org.apache.taglibs</groupId>
<artifactId>taglibs-standard-spec</artifactId>
<version> 1.2.6.RC1-redhat-1</version>
</dependency>
<!-- https://mvnrepository.com/artifact/org.apache.taglibs/taglibs-standard-impl -->
<dependency>
<groupId>org.apache.taglibs</groupId>
<artifactId>taglibs-standard-impl</artifactId>
<version> 1.2.6.RC1-redhat-1</version>
</dependency>
<!-- https://mvnrepository.com/artifact/org.apache.taglibs/taglibs-standard-jstlel -->
<dependency>
<groupId>org.apache.taglibs</groupId>
<artifactId>taglibs-standard-compat</artifactId>
<version>1.2.6.RC1-redhat-1</version>
</dependency>
.png)
HI @SGaurav140689 (Community Member) ,
Unfortunately, it is impossible for us to say whether these jars will work in your application as it depends on how your application uses these dependencies.
I would recommend replacing the jars and running tests on your application.
I would also recommend not using an RC version but using the latest stable 1.2.5 (latest version has no known vulnerabilities at this time: https://sca.analysiscenter.veracode.com/vulnerability-database/libraries/apache-standard-taglib-implementation/java/maven/lid-8119/summary ).
Thank you,
Boy Baukema