All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2021-09-19T00:00:00
Updated: 2024-08-04T02:51:06.487Z
Reserved: 2021-09-08T00:00:00
Link: CVE-2021-40690
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-09-19T18:15:07.223
Modified: 2023-11-07T03:38:37.593
Link: CVE-2021-40690
Redhat