PT-2020-13334 · Oasis · Oasis Digital Signature Services

Published

2020-08-24

·

Updated

2022-12-06

·

CVE-2020-13101

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions OASIS Digital Signature Services (DSS) version 1.0
Description The issue allows an attacker to control the validation outcome of a signature via a crafted XML signature when the InlineXML option is used, defeating the expectation of non-repudiation. This can result in either a valid or invalid outcome for a valid or invalid signature.
Recommendations For OASIS Digital Signature Services (DSS) version 1.0, consider disabling the InlineXML option as a temporary workaround until a patch is available. Restrict access to the XML signature validation mechanism to minimize the risk of exploitation. Avoid using the crafted XML signature feature in the affected version until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

CVE-2020-13101

Affected Products

Oasis Digital Signature Services