Exposure of Sensitive Information to an Unauthorized Actor in Apache Santuario
High severity
GitHub Reviewed
Published
Sep 20, 2021
to the GitHub Advisory Database
•
Updated Aug 18, 2023
Package
Affected versions
>= 2.2.0, < 2.2.3
< 2.1.7
Patched versions
2.2.3
2.1.7
Description
Published by the National Vulnerability Database
Sep 19, 2021
Reviewed
Sep 20, 2021
Published to the GitHub Advisory Database
Sep 20, 2021
Last updated
Aug 18, 2023
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
References