QID 980296
QID 980296: Java (maven) Security Update for org.apache.santuario:xmlsec (GHSA-4q98-wr72-h35w)
In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread context class loader first, then this implementation might be cached and re-used by Apache Santuario - XML Security for Java, leading to potential security flaws when validating signed documents, etc. The vulnerability affects Apache Santuario - XML Security for Java 2.0.x releases from 2.0.3 and all 2.1.x releases before 2.1.4.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-4q98-wr72-h35w for updates pertaining to this vulnerability.
Vendor References
- GHSA-4q98-wr72-h35w -
github.com/advisories/GHSA-4q98-wr72-h35w
CVEs related to QID 980296
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4q98-wr72-h35w | org.apache.santuario:xmlsec |
|