Description
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2767-1 | libxml-security-java security update |
Debian DSA |
DSA-5010-1 | libxml-security-java security update |
EUVD |
EUVD-2021-2083 | All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element. |
Github GHSA |
GHSA-j8wc-gxx9-82hx | Exposure of Sensitive Information to an Unauthorized Actor in Apache Santuario |
Ubuntu USN |
USN-5525-1 | Apache XML Security for Java vulnerability |
References
History
Mon, 28 Apr 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat jboss Enterprise Application Platform Eus
|
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7 | |
| Vendors & Products |
Redhat jboss Enterprise Application Platform Eus
|
Subscriptions
Apache
Subscribe
Cxf
Subscribe
Santuario Xml Security For Java
Subscribe
Tomee
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Oracle
Subscribe
Agile Plm
Subscribe
Commerce Guided Search
Subscribe
Commerce Platform
Subscribe
Communications Diameter Intelligence Hub
Subscribe
Communications Messaging Server
Subscribe
Flexcube Private Banking
Subscribe
Outside In Technology
Subscribe
Peoplesoft Enterprise Peopletools
Subscribe
Retail Bulk Data Integration
Subscribe
Retail Financial Integration
Subscribe
Retail Integration Bus
Subscribe
Retail Merchandising System
Subscribe
Retail Service Backbone
Subscribe
Weblogic Server
Subscribe
Redhat
Subscribe
Camel Quarkus
Subscribe
Integration
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Application Platform Eus
Subscribe
Jboss Fuse
Subscribe
Jbosseapxp
Subscribe
Red Hat Single Sign On
Subscribe
Rhosemc
Subscribe
Service Registry
Subscribe
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T02:51:06.487Z
Reserved: 2021-09-08T00:00:00.000Z
Link: CVE-2021-40690
No data.
Status : Modified
Published: 2021-09-19T18:15:07.223
Modified: 2024-11-21T06:24:34.267
Link: CVE-2021-40690
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN