Lucene search

K
cvelistApacheCVELIST:CVE-2019-12400
HistoryAug 23, 2019 - 8:30 p.m.

CVE-2019-12400

2019-08-2320:30:33
apache
www.cve.org
8

AI Score

7.3

Confidence

High

EPSS

0.002

Percentile

58.2%

In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread context class loader first, then this implementation might be cached and re-used by Apache Santuario - XML Security for Java, leading to potential security flaws when validating signed documents, etc. The vulnerability affects Apache Santuario - XML Security for Java 2.0.x releases from 2.0.3 and all 2.1.x releases before 2.1.4.

CNA Affected

[
  {
    "product": "Apache Santuario - XML Security for Java",
    "vendor": "Apache",
    "versions": [
      {
        "status": "affected",
        "version": "All 2.0.x releases from 2.0.3"
      },
      {
        "status": "affected",
        "version": "all 2.1.x releases before 2.1.4."
      }
    ]
  }
]

References

AI Score

7.3

Confidence

High

EPSS

0.002

Percentile

58.2%