CVE-2019-12400
MEDIUMApache Santuario XML Security for Java <2.0.3 - Info Disclosure
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2019-12400. PoCs published by dawetmaster, andikahilmy.
AI-analyzed exploit summary This repository contains the vulnerable source code of Apache Santuario Java, specifically the components affected by CVE-2019-12400, an XML signature wrapping vulnerability. It includes the original Java classes and a plotting script for performance analysis, but no functional exploit code.
Description
In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread context class loader first, then this implementation might be cached and re-used by Apache Santuario - XML Security for Java, leading to potential security flaws when validating signed documents, etc. The vulnerability affects Apache Santuario - XML Security for Java 2.0.x releases from 2.0.3 and all 2.1.x releases before 2.1.4.
Exploits (2)
This repository contains the vulnerable source code of Apache Santuario Java, specifically the components affected by CVE-2019-12400, an XML signature wrapping vulnerability. It includes the original Java classes and a plotting script for performance analysis, but no functional exploit code.
This repository contains a vulnerable version of Apache Santuario Java, specifically targeting CVE-2019-12400, which involves XML signature wrapping attacks. The provided code includes modified Java classes that demonstrate the vulnerability in the XML digital signature processing.
References (14)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N