CVE-2021-40690

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
VendorProductVersion
apachesantuario_xml_security_for_java
𝑥
< 2.1.7
apachesantuario_xml_security_for_java
2.2.0 ≤
𝑥
< 2.2.3
apachecxf
3.4.4
apachetomee
𝑥
< 8.0.8
debiandebian_linux
9.0
debiandebian_linux
10.0
debiandebian_linux
11.0
oracleagile_plm
9.3.6
oraclecommerce_guided_search
11.3.2
oraclecommerce_platform
11.3.2
oraclecommunications_diameter_intelligence_hub
8.0.0 ≤
𝑥
≤ 8.1.0
oraclecommunications_diameter_intelligence_hub
8.2.0 ≤
𝑥
≤ 8.2.3
oraclecommunications_messaging_server
8.1
oracleflexcube_private_banking
12.1.0
oracleoutside_in_technology
8.5.5
oraclepeoplesoft_enterprise_peopletools
8.58
oraclepeoplesoft_enterprise_peopletools
8.59
oracleretail_bulk_data_integration
16.0.3
oracleretail_financial_integration
14.1.3.2
oracleretail_financial_integration
15.0.3.1
oracleretail_financial_integration
16.0.3
oracleretail_financial_integration
19.0.1
oracleretail_integration_bus
14.1.3.2
oracleretail_integration_bus
15.0.3.1
oracleretail_integration_bus
16.0.3
oracleretail_integration_bus
19.0.1
oracleretail_merchandising_system
16.0.3
oracleretail_merchandising_system
19.0.1
oracleretail_service_backbone
14.1.3.2
oracleretail_service_backbone
15.0.3.1
oracleretail_service_backbone
16.0.3
oracleretail_service_backbone
19.0.1
oracleweblogic_server
12.2.1.4.0
oracleweblogic_server
14.1.1.0.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libxml-security-java
bullseye (security)
2.0.10-2+deb11u1
fixed
bullseye
2.0.10-2+deb11u1
fixed
bookworm
2.1.7-3
fixed
sid
2.1.8-1
fixed
trixie
2.1.8-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libxml-security-java
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
impish
ignored
hirsute
ignored
focal
Fixed 2.0.10-2+deb11u1build0.20.04.1
released
bionic
Fixed 2.0.10-2~18.04.1
released
xenial
needed
trusty
dne
References