ZeroHour

CVE-2021-40690

CVSS 3.1
7.5 high
EPSS
7%p94
Published
()
Modified
Description

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.

Vendors
apachedebianoracle
Products
santuario xml security for java, cxf, tomee, debian linux, agile product lifecycle management, commerce guided search, commerce platform, communications diameter intelligence hub, communications messaging server, flexcube private banking, outside in technology, peoplesoft enterprise peopletools
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.