Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11241
HistoryJan 15, 2019 - 8:59 a.m.

Spoofable XML Signature

2019-01-1508:59:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.005 Low

EPSS

Percentile

76.1%

Apache Santuario XML Security is vulnerable to Spoofable XML Signature. The use of weak CanonicalizationMethod in jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to specify an arbitrary weak canonicalization algorithm to apply to the SignedInfo part of the Signature.

References