CVE-2023-44483
- EPSS 0.13%
- Published 20.10.2023 10:15:12
- Last modified 13.02.2025 17:17:14
All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclosed in log files when generating an XML Signature and logging with debu...
CVE-2021-40690
- EPSS 0.44%
- Published 19.09.2021 18:15:07
- Last modified 21.11.2024 06:24:34
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacke...
CVE-2019-12400
- EPSS 0.32%
- Published 23.08.2019 21:15:11
- Last modified 21.11.2024 04:22:45
In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with t...
- EPSS 3.96%
- Published 21.01.2015 18:59:04
- Last modified 12.04.2025 10:46:40
Apache Santuario XML Security for Java 2.0.x before 2.0.3 allows remote attackers to bypass the streaming XML signature protection mechanism via a crafted XML document.
CVE-2013-4517
- EPSS 10.36%
- Published 11.01.2014 01:55:03
- Last modified 11.04.2025 00:51:21
Apache Santuario XML Security for Java before 1.5.6, when applying Transforms, allows remote attackers to cause a denial of service (memory consumption) via crafted Document Type Definitions (DTDs), related to signatures.
CVE-2013-2172
- EPSS 5.45%
- Published 20.08.2013 22:55:04
- Last modified 11.04.2025 00:51:21
jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to...