cbcvebase.
CVE-2013-2172
published 2013-08-20

CVE-2013-2172: jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows…

PriorityP431medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
5.93%
92.4th percentile
jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to specify an arbitrary weak "canonicalization algorithm to apply to the SignedInfo part of the Signature."

Affected

7 ranges
VendorProductVersion rangeFixed in
apachesantuario_xml_security_for_java
apachesantuario_xml_security_for_java
apachesantuario_xml_security_for_java
apachesantuario_xml_security_for_java
apachesantuario_xml_security_for_java
apachesantuario_xml_security_for_java
debianlibxml-security-java< libxml-security-java 1.5.5-2 (bookworm)libxml-security-java 1.5.5-2 (bookworm)

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.