FixVibe

// 代码 / 聚焦

veraPDF XSLT Injection Dependency Advisory

Affected veraPDF policy-file processing can put XSLT execution boundaries at risk.

概要

veraPDF is often used in document validation pipelines where policy files and Schematron profiles can become part of the processing surface. CVE-2024-28109 is tied to affected veraPDF packages before their fixed release lines; FixVibe treats a repo match as dependency evidence, not proof that custom policy files are attacker-controlled in production.

運作方式

The repo check looks for affected `org.verapdf` Maven coordinates in Java build files. Exact declared versions produce the strongest signal, including versions referenced through local Maven properties. The finding stays scoped to dependency evidence and does not claim FixVibe ran veraPDF, processed policy files, or executed XSLT.

影響范圍

If an affected veraPDF runtime processes untrusted custom policy files under the advisory conditions, XSLT behavior may cross into sensitive file or code-execution boundaries. A repo match should trigger dependency-tree review, runtime input review, artifact rebuild, and deployment verification before anyone treats it as confirmed exploitability.

// fixvibe 檢查的內容

FixVibe 檢查的內容

FixVibe repo scans look for high-confidence security patterns and dependency risk in source context. Reports identify the affected area and recommended fix. For check-specific questions about exact detection heuristics, active payload details, or source-code rule patterns, contact support@fixvibe.app.

铁壁防御

Upgrade affected veraPDF artifacts to the package-specific fixed version, regenerate Maven or Gradle metadata, and rebuild the deployed artifact or image. If the app accepts custom veraPDF policy files or validation profiles, allow only trusted sources and verify secure XSLT processing settings remain enabled after the upgrade.

// 在你自己的應用上跑一遍

放心继續發布,FixVibe 持續幫你看守風险。

FixVibe 像攻击者一樣對你的應用公開面进行压力测試 —— 无代理、无安裝、无信用卡。我們持續研究新的漏洞模式,并把它們转化成实用检查和可直接用于 Cursor、Claude、Copilot 的修複方案。

源代码
160
本類别中触發的测試
模塊
120
專属 源代码 检查
每次扫描
540+
跨所有類别的测試
  • 免费 —— 无需信用卡,无需安裝,无需 Slack 通知
  • 只需粘贴 URL —— 我們爬取、探测、生成報告
  • 按严重程度分级,去重至只剩信號
  • AI-ready prompts where code applies, plus operator steps for DNS/provider fixes
運行免费扫描

// 最新检查 · 实用修複 · 安心發布

veraPDF XSLT Injection Dependency Advisory — 漏洞聚焦 | FixVibe · FixVibe