V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
BDU:2023-07907
BDU
High

Уязвимость платформы для обеспечения безопасности XML-данных в приложениях на языке Java XML Apache Santuario XML Security for Java связана…

CVSS
7.5
High
EPSS
0.00
p0
Published
2023-01-01
Updated
2023-01-01
Description

Уязвимость платформы для обеспечения безопасности XML-данных в приложениях на языке Java XML Apache Santuario XML Security for Java связана с ошибками при передачи свойства "secureValidation" при создании объекта KeyInfo из элемента KeyInfoReference. Эксплуатация уязвимости может позволить нарушителю, действующему удалённо, получить доступ к произвольным файлам с расширением .xml через элемент RetrievalMethod

Tags · CWE
Pre-auth
Affected products
Apache software foundation CxfApache software foundation CxfApache software foundation CxfApache software foundation CxfApache software foundation Santuario xml securityApache software foundation Santuario xml securityApache software foundation Santuario xml securityApache software foundation Santuario xml securityApache software foundation Santuario xml securityApache software foundation Santuario xml securityApache software foundation Santuario xml securityApache software foundation Santuario xml securityApache software foundation TomeeApache software foundation TomeeApache software foundation TomeeApache software foundation TomeeElastic nv ElasticsearchElastic nv ElasticsearchElastic nv ElasticsearchElastic nv Elasticsearch
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Timeline
2023-01-01
Published
2023-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.000 · p0
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
cxfapache software foundationTracked
cxfapache software foundationTracked
cxfapache software foundationTracked
cxfapache software foundationTracked
santuario xml securityapache software foundationTracked
santuario xml securityapache software foundationTracked
santuario xml securityapache software foundationTracked
santuario xml securityapache software foundationTracked
santuario xml securityapache software foundationTracked
santuario xml securityapache software foundationTracked
santuario xml securityapache software foundationTracked
santuario xml securityapache software foundationTracked
tomeeapache software foundationTracked
tomeeapache software foundationTracked
tomeeapache software foundationTracked
tomeeapache software foundationTracked
elasticsearchelastic nvTracked
elasticsearchelastic nvTracked
elasticsearchelastic nvTracked
elasticsearchelastic nvTracked
Showing first 20 of 124
Source databases
BDU
Related vulnerabilities
External references
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-40690@https://lists.apache.org/thread.html/r3b3f5ba9b0de8c9c125077b71af06026d344a709a8ba67db81ee9faa%40%3Ccommits.tomee.apache.org%3E@https://lists.apache.org/thread.html/r401ecb7274794f040cd757b259ebe3e8c463ae74f7961209ccad3c59%40%3Cissues.cxf.apache.org%3E@https://lists.apache.org/thread.html/r8848751b6a5dd78cc9e99d627e74fecfaffdfa1bb615dce827aad633%40%3Cdev.santuario.apache.org%3E@https://lists.apache.org/thread.html/r8a5c0ce9014bd07303aec1e5eed55951704878016465d3dae00e0c28%40%3Ccommits.tomee.apache.org%3E@https://lists.apache.org/thread.html/r9c100d53c84d54cf71975e3f0cfcc2856a8846554a04c99390156ce4%40%3Ccommits.tomee.apache.org%3E@https://lists.apache.org/thread.html/raf352f95c19c0c4051af3180752cb69acbea88d0d066ab176c6170e8%40%3Cuser.poi.apache.org%3E@https://lists.apache.org/thread.html/rbbbac0759b12472abd0c278d32b5e0867bb21934df8e14e5e641597c%40%3Ccommits.tomee.apache.org%3E@https://lists.apache.org/thread.html/rbdac116aef912b563da54f4c152222c0754e32fb2f785519ac5e059f%40%3Ccommits.tomee.apache.org%3E@https://lists.apache.org/thread.html/re294cfc61f509512874ea514d8d64fd276253d54ac378ffa7a4880c8%40%3Ccommits.tomee.apache.org%3E@https://lists.debian.org/debian-lts-announce/2021/09/msg00015.html@https://security.netapp.com/advisory/ntap-20230818-0002/@https://www.debian.org/security/2021/dsa-5010@https://www.oracle.com/security-alerts/cpuapr2022.html@https://www.oracle.com/security-alerts/cpujul2022.html@https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.4.2/