CVE-2021-40690

CVE-2021-40690

All versions of Apache Santuario – XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.

Source: CVE-2021-40690

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다