Lucene search

K
ubuntuUbuntuUSN-6274-1
HistoryAug 03, 2023 - 12:00 a.m.

XMLTooling vulnerability

2023-08-0300:00:00
ubuntu.com
24
ubuntu 16.04 esm
xmltooling
encryption support
keyinfo
xml signature
server-side request forgery
unix

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.8

Confidence

High

EPSS

0.001

Percentile

47.0%

Releases

  • Ubuntu 16.04 ESM

Packages

  • xmltooling - C++ XML parsing library with encryption support

Details

Jurien de Jong discovered that XMLTooling did not properly handle certain
KeyInfo element content within an XML signature. An attacker could possibly
use this issue to achieve server-side request forgery.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.8

Confidence

High

EPSS

0.001

Percentile

47.0%