PT-2021-7970 · Apache+4 · Apache Santuario Xml Security For Java+5

Published

2021-09-19

·

Updated

2024-06-15

·

CVE-2021-40690

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Santuario - XML Security for Java versions prior to 2.2.3 and 2.1.7
Description The issue is related to the secureValidation property not being passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
Recommendations For Apache Santuario - XML Security for Java versions prior to 2.2.3, upgrade to version 2.2.3 or later. For Apache Santuario - XML Security for Java versions prior to 2.1.7, upgrade to version 2.1.7 or later. As a temporary workaround, consider restricting access to the RetrievalMethod element to minimize the risk of exploitation. Avoid using the secureValidation property in the affected KeyInfo creation until the issue is resolved.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-07907
CVE-2021-40690
DLA-2767-1
DSA-5010-1
GHSA-J8WC-GXX9-82HX
OPENSUSE-SU-2024:11693-1
RHSA-2021:5149
RHSA-2021:5150
RHSA-2021:5151
RHSA-2022:0151
RHSA-2022:0152
RHSA-2025:4226
USN-5525-1

Affected Products

Apache Santuario Xml Security For Java
Astra Linux
Bitbucket
Jira
Linuxmint
Ubuntu