Hi Srujith, On Fri, Apr 7, 2023 at 11:33 AM SRUJITH PULIPAKA <srujit...@gmail.com> wrote:
> I see that Xalan 2.7.3 is released as mentioned in the > https://xalan.apache.org/ > I need confirmation whether CVE-2022-34169 is solved by this update or not Yes, I can confirm that, XalanJ 2.7.3 solves the bug illustrated by CVE-2022-34169. The fix for this bug, may also be tested by one of the XalanJ tests available at https://github.com/apache/xalan-test/tree/master/tests/2.7.3_release. -- Regards, Mukul Gandhi