CVE-2023-34205
30.05.2023, 04:15
In Moov signedxml through 1.0.0, parsing the raw XML (as received) can result in different output than parsing the canonicalized XML. Thus, signature validation can be bypassed via a Signature Wrapping attack (aka XSW).Enginsight
Vendor | Product | Version |
---|---|---|
moov | signedxml | 1.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration