Hi Srujith,

On Fri, Apr 7, 2023 at 11:33 AM SRUJITH PULIPAKA <srujit...@gmail.com> wrote:

> I see that Xalan 2.7.3 is released as mentioned in the 
> https://xalan.apache.org/
> I need confirmation whether CVE-2022-34169 is solved by this update or not

Yes, I can confirm that, XalanJ 2.7.3 solves the bug illustrated by
CVE-2022-34169. The fix for this bug, may also be tested by one of the
XalanJ tests available at
https://github.com/apache/xalan-test/tree/master/tests/2.7.3_release.


-- 
Regards,
Mukul Gandhi

Reply via email to