CVE-2023-44483
Summary
| CVE | CVE-2023-44483 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-20 10:15:00 UTC |
| Updated | 2023-10-27 18:49:00 UTC |
| Description | All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclosed in log files when generating an XML Signature and logging with debug level is enabled. Users are recommended to upgrade to version 2.2.6, 2.3.4, or 3.0.3, which fixes this issue. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| lists.apache.org/thread/vmqbp9mfxtrf0kmbnnmbn3h9j6dr9q55 |
MISC |
lists.apache.org |
|
| oss-security - CVE-2023-44483: Apache Santuario: Private Key disclosure in debug-log output |
MISC |
www.openwall.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 150788 Oracle WebLogic Server Multiple Vulnerabilities (CPUJAN2024)
- 242821 Red Hat Update for JBoss Enterprise Application Platform 7.4.1 (RHSA-2024:0712)
- 242822 Red Hat Update for JBoss Enterprise Application Platform 7.4.1 (RHSA-2024:0710)
- 242823 Red Hat Update for JBoss Enterprise Application Platform 7.4.1 (RHSA-2024:0711)
- 379027 IBM WebSphere Application Server Liberty Information Disclosure Vulnerability (7076305)
- 87550 Oracle WebLogic Server Multiple Vulnerabilities (CPUJAN2024)
- 995676 Java (Maven) Security Update for org.apache.santuario:xmlsec (GHSA-xfrj-6vvc-3xm2)