CVE-2019-12400
MEDIUMApache Santuario XML Security for Java <2.0.3 - Info Disclosure
Title source: llmDescription
In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread context class loader first, then this implementation might be cached and re-used by Apache Santuario - XML Security for Java, leading to potential security flaws when validating signed documents, etc. The vulnerability affects Apache Santuario - XML Security for Java 2.0.x releases from 2.0.3 and all 2.1.x releases before 2.1.4.
Exploits (2)
nomisec
WRITEUP
by dawetmaster · poc
https://github.com/dawetmaster/CVE-2019-12400-santuario-java-vulnerable
nomisec
WORKING POC
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2019-12400-santuario-java-vulnerable
References (14)
Scores
CVSS v3
5.5
EPSS
0.0059
EPSS Percentile
69.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-20
Status
published
Products (5)
apache/santuario_xml_security_for_java
2.0.3 - 2.0.10
oracle/weblogic_server
12.2.1.4.0
oracle/weblogic_server
14.1.1.0.0
org.apache.santuario/xmlsec
2.0.3 - 2.1.4Maven
redhat/jboss_enterprise_application_platform
7.2
Published
Aug 23, 2019
Tracked Since
Feb 18, 2026