CVE Database
/

CVE-2021-40690

Back to search

CVE-2021-40690

Published: Sep 19, 2021

Modified: Aug 4, 2024

PUBLISHED

Description

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.

VendorProductVersions

Apache Software Foundation

Apache Santuario

affected
XML Security for Java - < 2.2.3,2.1.7

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now