All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Atlassian Bitbucket | — | Upgrade Atlassian Bitbucket to the latest version | Nov 14, 2024 | Nov 21, 2023 |
| Debian | — | Upgrade libxml-security-java | Sep 29, 2021 | Sep 19, 2021 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 34236279 for version 12.2.1.4.0.Apply the Patch Set Update (PSU) 34298772 for version 12.2.1.3.0.Apply the Patch Set Update (PSU) 34429365 for version 14.1.1.0.0. | Jul 25, 2022 | Sep 19, 2021 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Sep 17, 2021 |
| Red_hat Jboss_eap | — | — | Apr 10, 2023 | Sep 19, 2021 |
| Ubuntu | — | Upgrade libxml-security-java | Mar 22, 2023 | Sep 19, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub