Improper Input Validation in Apache Santuario XML Security
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Apr 12, 2024
Package
Affected versions
>= 2.0.0, < 2.0.3
Patched versions
2.0.3
Description
Published by the National Vulnerability Database
Jan 21, 2015
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jul 6, 2022
Last updated
Apr 12, 2024
Apache Santuario XML Security for Java 2.0.x before 2.0.3 allows remote attackers to bypass the streaming XML signature protection mechanism via a crafted XML document.
References