In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread context class loader first, then this implementation might be cached and re-used by Apache Santuario - XML Security for Java, leading to potential security flaws when validating signed documents, etc. The vulnerability affects Apache Santuario - XML Security for Java 2.0.x releases from 2.0.3 and all 2.1.x releases before 2.1.4.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libxml-security-java | Jul 30, 2024 | Aug 23, 2019 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 33416881 for version 14.1.1.0.0.Apply the Patch Set Update (PSU) 33416868 for version 12.2.1.4.0. | Feb 28, 2022 | Aug 23, 2019 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Aug 23, 2019 |
| Red_hat Jboss_eap | — | — | Jun 24, 2022 | Aug 23, 2019 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Aug 23, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub