CVE-2021-40690
—CVSS 3.1
7.5 high
EPSS
7%p94
Published
()
Modified
Description
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
- Vendors
- apachedebianoracle
- Products
- santuario xml security for java, cxf, tomee, debian linux, agile product lifecycle management, commerce guided search, commerce platform, communications diameter intelligence hub, communications messaging server, flexcube private banking, outside in technology, peoplesoft enterprise peopletools
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.