Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3rvj-2vfj-frq8

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The XML digital signature functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows context-dependent attackers to reuse signatures and spoof arbitrary content via crafted Reference elements in the Signature, aka "XML Signature Bypass issue."

The XML digital signature functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows context-dependent attackers to reuse signatures and spoof arbitrary content via crafted Reference elements in the Signature, aka "XML Signature Bypass issue."

EPSS

Процентиль: 74%
0.00835
Низкий

Связанные уязвимости

ubuntu
больше 12 лет назад

The XML digital signature functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows context-dependent attackers to reuse signatures and spoof arbitrary content via crafted Reference elements in the Signature, aka "XML Signature Bypass issue."

nvd
больше 12 лет назад

The XML digital signature functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows context-dependent attackers to reuse signatures and spoof arbitrary content via crafted Reference elements in the Signature, aka "XML Signature Bypass issue."

debian
больше 12 лет назад

The XML digital signature functionality (xsec/dsig/DSIGReference.cpp) ...

EPSS

Процентиль: 74%
0.00835
Низкий