Description
jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to specify an arbitrary weak "canonicalization algorithm to apply to the SignedInfo part of the Signature."
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-85-1 | libxml-security-java security update |
Debian DSA |
DSA-3065-1 | libxml-security-java security update |
EUVD |
EUVD-2022-5065 | jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to specify an arbitrary weak "canonicalization algorithm to apply to the SignedInfo part of the Signature." |
Github GHSA |
GHSA-r237-w2w6-jq3p | Inefficient Algorithmic Complexity in Apache Santuario XML Security |
Ubuntu USN |
USN-2028-1 | Apache XML Security for Java vulnerability |
References
History
No history.
Subscriptions
Apache
Subscribe
Santuario Xml Security For Java
Subscribe
Redhat
Subscribe
Fuse Esb Enterprise
Subscribe
Fuse Management Console
Subscribe
Fuse Mq Enterprise
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Brms Platform
Subscribe
Jboss Enterprise Portal Platform
Subscribe
Jboss Enterprise Soa Platform
Subscribe
Jboss Enterprise Web Platform
Subscribe
Jboss Fuse
Subscribe
Jboss Operations Network
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T15:27:41.140Z
Reserved: 2013-02-19T00:00:00.000Z
Link: CVE-2013-2172
No data.
Status : Deferred
Published: 2013-08-20T22:55:04.093
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-2172
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN