CVE-2021-40690

HIGH

Apache Santuario XML Security for Java < 2.1.7 - Sensitive Information Exposure via XPath Transform

Title source: llm
STIX 2.1

Description

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.

References (14)

Core 14
Core References
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2021/09/msg00015.html
Third Party Advisory vendor-advisory
https://www.debian.org/security/2021/dsa-5010

Scores

CVSS v3 7.5
EPSS 0.0028
EPSS Percentile 51.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (33)
apache/cxf 3.4.4
apache/santuario_xml_security_for_java < 2.1.7
apache/tomee < 8.0.8
debian/debian_linux 9.0
debian/debian_linux 10.0
debian/debian_linux 11.0
oracle/agile_plm 9.3.6
oracle/commerce_guided_search 11.3.2
oracle/commerce_platform 11.3.2
oracle/communications_diameter_intelligence_hub 8.0.0 - 8.1.0
... and 23 more
Published Sep 19, 2021
Tracked Since Feb 18, 2026