Описание
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 2.0.10-2~18.04.1 |
| devel | not-affected | 2.1.7-2 |
| esm-apps/bionic | released | 2.0.10-2~18.04.1 |
| esm-apps/focal | released | 2.0.10-2+deb11u1build0.20.04.1 |
| esm-apps/jammy | not-affected | 2.1.7-2 |
| esm-apps/noble | not-affected | 2.1.7-2 |
| esm-apps/xenial | needed | |
| esm-infra-legacy/trusty | DNE | |
| focal | released | 2.0.10-2+deb11u1build0.20.04.1 |
| hirsute | ignored | end of life |
Показывать по
Ссылки на источники
EPSS
5 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
All versions of Apache Santuario - XML Security for Java prior to 2.2. ...
Exposure of Sensitive Information to an Unauthorized Actor in Apache Santuario
Уязвимость платформы для обеспечения безопасности XML-данных в приложениях на языке Java XML Apache Santuario XML Security for Java, связанная с ошибками при передачи свойства "secureValidation" при создании объекта KeyInfo из элемента KeyInfoReference, позволяющая нарушителю получить доступ к произвольным файлам с расширением .xml
EPSS
5 Medium
CVSS2
7.5 High
CVSS3