PT-2023-6589 · Apache+1 · Apache Santuario Xml Security For Java+1
Max Fichtelmann
·
Publicado
2023-10-19
·
Atualizado
2025-10-11
·
CVE-2023-44483
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Santuario - XML Security for Java versions prior to 2.2.6
Apache Santuario - XML Security for Java versions prior to 2.3.4
Apache Santuario - XML Security for Java versions prior to 3.0.3
Description
The issue is related to the disclosure of information through log files. When using the JSR 105 API and generating an XML Signature with debug level logging enabled, a private key may be disclosed in log files.
Recommendations
Upgrade to version 2.2.6, which fixes this issue.
Upgrade to version 2.3.4, which fixes this issue.
Upgrade to version 3.0.3, which fixes this issue.
Correção
Insertion into Log File
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Santuario Xml Security For Java
Debian