Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-40690
HistorySep 19, 2021 - 6:15 p.m.

Code injection

2021-09-1918:15:00
PRIOn knowledge base
www.prio-n.com
7

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.9%

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the β€œsecureValidation” property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.

References