CVE-2013-2172
published 2013-08-20CVE-2013-2172: jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows…
PriorityP431medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
5.93%
92.4th percentile
jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to specify an arbitrary weak "canonicalization algorithm to apply to the SignedInfo part of the Signature."
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | santuario_xml_security_for_java | — | — |
| apache | santuario_xml_security_for_java | — | — |
| apache | santuario_xml_security_for_java | — | — |
| apache | santuario_xml_security_for_java | — | — |
| apache | santuario_xml_security_for_java | — | — |
| apache | santuario_xml_security_for_java | — | — |
| debian | libxml-security-java | < libxml-security-java 1.5.5-2 (bookworm) | libxml-security-java 1.5.5-2 (bookworm) |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Inefficient Algorithmic Complexity in Apache Santuario XML Security
ghsa·2022-05-13
CVE-2013-2172 [MEDIUM] CWE-407 Inefficient Algorithmic Complexity in Apache Santuario XML Security
Inefficient Algorithmic Complexity in Apache Santuario XML Security
`jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java` in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to specify an arbitrary weak "canonicalization algorithm to apply to the SignedInfo part of the Signature."
OSV
Inefficient Algorithmic Complexity in Apache Santuario XML Security
osv·2022-05-13
CVE-2013-2172 [MEDIUM] Inefficient Algorithmic Complexity in Apache Santuario XML Security
Inefficient Algorithmic Complexity in Apache Santuario XML Security
`jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java` in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to specify an arbitrary weak "canonicalization algorithm to apply to the SignedInfo part of the Signature."
OSV
CVE-2013-2172: jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod
osv·2013-08-20·CVSS 4.3
CVE-2013-2172 [MEDIUM] CVE-2013-2172: jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod
jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to specify an arbitrary weak "canonicalization algorithm to apply to the SignedInfo part of the Signature."
Ubuntu
Apache XML Security for Java vulnerability
vendor_ubuntu·2013-11-12
CVE-2013-2172 Apache XML Security for Java vulnerability
Title: Apache XML Security for Java vulnerability
Summary: Apache XML Security for Java could be tricked into validating spoofed
signatures.
James Forshaw discovered that Apache XML Security for Java incorrectly
validated CanonicalizationMethod parameters. An attacker could use this
flaw to spoof XML signatures.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
Java: XML signature spoofing
vendor_redhat·2013-06-25·CVSS 4.3
CVE-2013-2172 [MEDIUM] CWE-290 Java: XML signature spoofing
Java: XML signature spoofing
jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to specify an arbitrary weak "canonicalization algorithm to apply to the SignedInfo part of the Signature."
A flaw was found in the way Apache Santuario XML Security for Java validated XML signatures. Santuario allowed a signature to specify an arbitrary canonicalization algorithm, which would be applied to the SignedInfo XML fragment. A remote attacker could exploit this to spoof an XML signature via a specially crafted XML signature block.
Package: xmlsec (Red Hat JBoss Enterprise Application Platform 4) - Will n
Debian
CVE-2013-2172: libxml-security-java - jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML...
vendor_debian·2013·CVSS 4.3
CVE-2013-2172 [MEDIUM] CVE-2013-2172: libxml-security-java - jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML...
jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to specify an arbitrary weak "canonicalization algorithm to apply to the SignedInfo part of the Signature."
Scope: local
bookworm: resolved (fixed in 1.5.5-2)
bullseye: resolved (fixed in 1.5.5-2)
forky: resolved (fixed in 1.5.5-2)
sid: resolved (fixed in 1.5.5-2)
trixie: resolved (fixed in 1.5.5-2)
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2013-1207.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1208.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1209.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1217.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1218.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1219.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1220.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1375.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1437.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1853.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0212.htmlhttp://santuario.apache.org/secadv.data/CVE-2013-2172.txt.aschttp://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/54019http://svn.apache.org/viewvc/santuario/xml-security-java/branches/1.5.x-fixes/src/main/java/org/apache/jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java?r1=1353876&r2=1493772&pathrev=1493772&diff_format=hhttp://www.debian.org/security/2014/dsa-3065http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.osvdb.org/94651http://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/60846http://www.ubuntu.com/usn/USN-2028-1http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://lists.apache.org/thread.html/680e6938b6412e26d5446054fd31de2011d33af11786b989127d1cc3%40%3Ccommits.santuario.apache.org%3Ehttps://lists.apache.org/thread.html/r1c07a561426ec5579073046ad7f4207cdcef452bb3100abaf908e0cd%40%3Ccommits.santuario.apache.org%3Ehttp://rhn.redhat.com/errata/RHSA-2013-1207.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1208.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1209.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1217.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1218.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1219.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1220.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1375.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1437.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1853.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0212.htmlhttp://santuario.apache.org/secadv.data/CVE-2013-2172.txt.aschttp://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/54019http://svn.apache.org/viewvc/santuario/xml-security-java/branches/1.5.x-fixes/src/main/java/org/apache/jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java?r1=1353876&r2=1493772&pathrev=1493772&diff_format=hhttp://www.debian.org/security/2014/dsa-3065http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.osvdb.org/94651http://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/60846http://www.ubuntu.com/usn/USN-2028-1http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://lists.apache.org/thread.html/680e6938b6412e26d5446054fd31de2011d33af11786b989127d1cc3%40%3Ccommits.santuario.apache.org%3Ehttps://lists.apache.org/thread.html/r1c07a561426ec5579073046ad7f4207cdcef452bb3100abaf908e0cd%40%3Ccommits.santuario.apache.org%3E
2013-08-20
Published