CVE-2013-2172

Apache Santuario XML Security for Java <1.4.8/1.5.5 XML Signature Spoofing

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2013-2172. PoCs published by dawetmaster, andikahilmy.

AI-analyzed exploit summary This repository contains functional Java code demonstrating CVE-2013-2172, a vulnerability in Apache Santuario XML Security for Java. The code includes samples for generating and validating XML signatures, which can be used to exploit the vulnerability.

Description

jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to specify an arbitrary weak "canonicalization algorithm to apply to the SignedInfo part of the Signature."

Exploits (2)

nomisec WORKING POC
by dawetmaster · poc
https://github.com/dawetmaster/CVE-2013-2172-santuario-java-vulnerable

This repository contains functional Java code demonstrating CVE-2013-2172, a vulnerability in Apache Santuario XML Security for Java. The code includes samples for generating and validating XML signatures, which can be used to exploit the vulnerability.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Apache Santuario XML Security for Java
No auth needed
Prerequisites: Java environment · Apache Santuario XML Security for Java library
devstral-2 · analyzed Mar 14, 2026 Full analysis →
nomisec WORKING POC
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2013-2172-santuario-java-vulnerable

This repository contains functional Java code demonstrating CVE-2013-2172, a vulnerability in Apache Santuario XML Security for Java. The code includes samples for generating and validating XML signatures, which can be used to exploit the vulnerability.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Apache Santuario XML Security for Java
No auth needed
Prerequisites: Java environment · Apache Santuario XML Security for Java library
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (24)

Core 24
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1219.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1218.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1209.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1217.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1437.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1207.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1375.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-0212.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1853.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1208.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1220.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/54019
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/534161/100/0/threaded
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2028-1
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Dec/23
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/60846
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/94651
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2014/dsa-3065

Scores

EPSS 0.0364
EPSS Percentile 88.2%

Details

CWE
CWE-310
Status published
Products (7)
apache/santuario_xml_security_for_java 1.4.7
apache/santuario_xml_security_for_java 1.5.0
apache/santuario_xml_security_for_java 1.5.1
apache/santuario_xml_security_for_java 1.5.2
apache/santuario_xml_security_for_java 1.5.3
apache/santuario_xml_security_for_java 1.5.4
org.apache.santuario/xmlsec 1.4.0 - 1.4.8Maven
Published Aug 20, 2013
Tracked Since Feb 18, 2026