Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:32164
HistorySep 20, 2021 - 3:36 a.m.

Bypass Of Secure Validation

2021-09-2003:36:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.001 Low

EPSS

Percentile

43.9%

Apache Santuario is vulnerable to bypass of secure validation. Lack of secure handling of secureValidation property allows an attacker to abuse an XPath Transform and to extract any local .xml files in a RetrievalMethod element during the creation of a KeyInfo from a KeyInfoReference element.

References