PT-2023-6589 · Apache+1 · Apache Santuario Xml Security For Java+1
Max Fichtelmann
·
Published
2023-10-19
·
Updated
2025-10-11
·
CVE-2023-44483
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Santuario - XML Security for Java versions prior to 2.2.6
Apache Santuario - XML Security for Java versions prior to 2.3.4
Apache Santuario - XML Security for Java versions prior to 3.0.3
Description
The issue is related to the disclosure of information through log files. When using the JSR 105 API and generating an XML Signature with debug level logging enabled, a private key may be disclosed in log files.
Recommendations
Upgrade to version 2.2.6, which fixes this issue.
Upgrade to version 2.3.4, which fixes this issue.
Upgrade to version 3.0.3, which fixes this issue.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Santuario Xml Security For Java
Debian