Fixed
Details
Assignee
Christian PapeChristian PapeReporter
Shobha RamachandrappaShobha RamachandrappaHB Grooming Date
Mar 19, 2024HB Backlog Status
Refined BacklogSprint
NoneFix versions
Affects versions
Priority
High
Details
Details
Assignee
Christian Pape
Christian PapeReporter
Shobha Ramachandrappa
Shobha RamachandrappaHB Grooming Date
Mar 19, 2024
HB Backlog Status
Refined Backlog
Sprint
None
Fix versions
Affects versions
Priority
PagerDuty
PagerDuty
PagerDuty
Created March 19, 2024 at 11:08 AM
Updated June 7, 2024 at 6:49 AM
Resolved June 7, 2024 at 6:49 AM
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.