All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Apache
Subscribe
|
|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Oracle
Subscribe
|
Agile Plm
Subscribe
Commerce Guided Search
Subscribe
Commerce Platform
Subscribe
Communications Diameter Intelligence Hub
Subscribe
Communications Messaging Server
Subscribe
Flexcube Private Banking
Subscribe
Outside In Technology
Subscribe
Peoplesoft Enterprise Peopletools
Subscribe
Retail Bulk Data Integration
Subscribe
Retail Financial Integration
Subscribe
Retail Integration Bus
Subscribe
Retail Merchandising System
Subscribe
Retail Service Backbone
Subscribe
Weblogic Server
Subscribe
|
|
Redhat
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2767-1 | libxml-security-java security update |
Debian DSA |
DSA-5010-1 | libxml-security-java security update |
EUVD |
EUVD-2021-2083 | All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element. |
Github GHSA |
GHSA-j8wc-gxx9-82hx | Exposure of Sensitive Information to an Unauthorized Actor in Apache Santuario |
Ubuntu USN |
USN-5525-1 | Apache XML Security for Java vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 28 Apr 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat jboss Enterprise Application Platform Eus
|
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7 | |
| Vendors & Products |
Redhat jboss Enterprise Application Platform Eus
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T02:51:06.487Z
Reserved: 2021-09-08T00:00:00
Link: CVE-2021-40690
No data.
Status : Modified
Published: 2021-09-19T18:15:07.223
Modified: 2024-11-21T06:24:34.267
Link: CVE-2021-40690
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN