jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to specify an arbitrary weak "canonicalization algorithm to apply to the SignedInfo part of the Signature."
Project Subscriptions
| Vendors | Products |
|---|---|
|
Apache
Subscribe
|
Santuario Xml Security For Java
Subscribe
|
|
Redhat
Subscribe
|
Fuse Esb Enterprise
Subscribe
Fuse Management Console
Subscribe
Fuse Mq Enterprise
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Brms Platform
Subscribe
Jboss Enterprise Portal Platform
Subscribe
Jboss Enterprise Soa Platform
Subscribe
Jboss Enterprise Web Platform
Subscribe
Jboss Fuse
Subscribe
Jboss Operations Network
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-85-1 | libxml-security-java security update |
Debian DSA |
DSA-3065-1 | libxml-security-java security update |
EUVD |
EUVD-2022-5065 | jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to specify an arbitrary weak "canonicalization algorithm to apply to the SignedInfo part of the Signature." |
Github GHSA |
GHSA-r237-w2w6-jq3p | Inefficient Algorithmic Complexity in Apache Santuario XML Security |
Ubuntu USN |
USN-2028-1 | Apache XML Security for Java vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T15:27:41.140Z
Reserved: 2013-02-19T00:00:00
Link: CVE-2013-2172
No data.
Status : Deferred
Published: 2013-08-20T22:55:04.093
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-2172
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN