CVE-2019-11068 - CVE House
Back to Database
Status published Unknown CVE-2019-11068

libxslt through 1.1.33 allows bypass of a protection mechanism because...

Vulnerability Description

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-11068

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

libxslt, ubuntu linux, debian linux, fedora, jdk, active iq unified manager, cloud backup, e-series santricity management plug-ins, e-series santricity os controller, e-series santricity storage manager, e-series santricity unified manager, e-series santricity web services proxy, element software, hci management node, oncommand insight, oncommand workflow automation, plug-in for symantec netbackup, santricity unified manager, snapmanager, solidfire, steelstore cloud integrated storage, leap
Vulnerable Versions:
0, 12.04, 14.04, 16.04, 18.04, 18.10, 8.0, 29, 30, 11.0, 15.0, 15.1, 42.3

Timeline

Official Publish: April 10th, 2019
Last Modified: May 28th, 2026
Added to House: July 20th, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.