CVE-2019-12400
published 2019-08-23CVE-2019-12400: In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of…
PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
EPSS
0.78%
51.7th percentile
In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread context class loader first, then this implementation might be cached and re-used by Apache Santuario - XML Security for Java, leading to potential security flaws when validating signed documents, etc. The vulnerability affects Apache Santuario - XML Security for Java 2.0.x releases from 2.0.3 and all 2.1.x releases before 2.1.4.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apache_santuario_xml_security_for_java | — | — |
| apache | apache_santuario_xml_security_for_java | — | — |
| apache | santuario_xml_security_for_java | 2.0.3 – 2.0.10 | — |
| apache | santuario_xml_security_for_java | >= 2.1.0 < 2.1.4 | 2.1.4 |
| debian | libxml-security-java | < libxml-security-java 2.1.7-1 (bookworm) | libxml-security-java 2.1.7-1 (bookworm) |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:P/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_oracle5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Web Services (Apache Santuario XML Security For Java) — CVE-2019-12400
vendor_oracle·2021-10-15·CVSS 5.5
CVE-2019-12400 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Web Services (Apache Santuario XML Security For Java) — CVE-2019-12400
Oracle Oracle Fusion Middleware Risk Matrix: Web Services (Apache Santuario XML Security For Java) vulnerability
CVE: CVE-2019-12400
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2021 (OCT 2021)
Red Hat
xml-security: Apache Santuario potentially loads XML parsing code from an untrusted source
vendor_redhat·2019-08-23·CVSS 5.5
CVE-2019-12400 [MEDIUM] CWE-20 xml-security: Apache Santuario potentially loads XML parsing code from an untrusted source
xml-security: Apache Santuario potentially loads XML parsing code from an untrusted source
In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread context class loader first, then this implementation might be cached and re-used by Apache Santuario - XML Security for Java, leading to potential security flaws when validating signed documents, etc. The vulnerability affects Apache Santuario - XML Security for Java 2.0.x releases from 2.0.3 and all 2.1.x releases before 2.1.4.
Package: xmlsec (Red Hat Decision Manager 7) - Not affected
Package: xmlsec (Red Hat JBoss BRMS 5) - Out of support
Debian
CVE-2019-12400: libxml-security-java - In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was...
vendor_debian·2019·CVSS 5.5
CVE-2019-12400 [MEDIUM] CVE-2019-12400: libxml-security-java - In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was...
In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread context class loader first, then this implementation might be cached and re-used by Apache Santuario - XML Security for Java, leading to potential security flaws when validating signed documents, etc. The vulnerability affects Apache Santuario - XML Security for Java 2.0.x releases from 2.0.3 and all 2.1.x releases before 2.1.4.
Scope: local
bookworm: resolved (fixed in 2.1.7-1)
bullseye: open
forky: resolved (fixed in 2.1.7-1)
sid: resolved (fixed in 2.1.7-1)
trixie: resolved (fixed in 2.1.7-1)
GHSA
Improper input validation in Apache Santuario XML Security for Java
ghsa·2019-08-27
CVE-2019-12400 [MEDIUM] CWE-20 Improper input validation in Apache Santuario XML Security for Java
Improper input validation in Apache Santuario XML Security for Java
In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread context class loader first, then this implementation might be cached and re-used by Apache Santuario - XML Security for Java, leading to potential security flaws when validating signed documents, etc. The vulnerability affects Apache Santuario - XML Security for Java 2.0.x releases from 2.0.3 and all 2.1.x releases before 2.1.4.
OSV
Improper input validation in Apache Santuario XML Security for Java
osv·2019-08-27
CVE-2019-12400 [MEDIUM] Improper input validation in Apache Santuario XML Security for Java
Improper input validation in Apache Santuario XML Security for Java
In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread context class loader first, then this implementation might be cached and re-used by Apache Santuario - XML Security for Java, leading to potential security flaws when validating signed documents, etc. The vulnerability affects Apache Santuario - XML Security for Java 2.0.x releases from 2.0.3 and all 2.1.x releases before 2.1.4.
OSV
CVE-2019-12400: In version 2
osv·2019-08-23·CVSS 5.5
CVE-2019-12400 [MEDIUM] CVE-2019-12400: In version 2
In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread context class loader first, then this implementation might be cached and re-used by Apache Santuario - XML Security for Java, leading to potential security flaws when validating signed documents, etc. The vulnerability affects Apache Santuario - XML Security for Java 2.0.x releases from 2.0.3 and all 2.1.x releases before 2.1.4.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-12400 xml-security: Apache Santuario potentially loads XML parsing code from an untrusted source
bugzilla·2019-10-23·CVSS 5.5
CVE-2019-12400 [MEDIUM] CVE-2019-12400 xml-security: Apache Santuario potentially loads XML parsing code from an untrusted source
CVE-2019-12400 xml-security: Apache Santuario potentially loads XML parsing code from an untrusted source
In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread context class loader first, then this implementation might be cached and re-used by Apache Santuario - XML Security for Java, leading to potential security flaws when validating signed documents, etc. The vulnerability affects Apache Santuario - XML Security for Java 2.0.x releases from 2.0.3 and all 2.1.x releases before 2.1.4.
References:
http://santuario.apache.org/secadv.data/CVE-2019-12400.asc?version=1&modificationDate=15
Bugzilla
CVE-2019-12400 xml-security: Apache Santuario potentially loads XML parsing code from an untrusted source [epel-all]
bugzilla·2019-10-23·CVSS 5.5
CVE-2019-12400 [MEDIUM] CVE-2019-12400 xml-security: Apache Santuario potentially loads XML parsing code from an untrusted source [epel-all]
CVE-2019-12400 xml-security: Apache Santuario potentially loads XML parsing code from an untrusted source [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issu
Bugzilla
CVE-2019-12400 xmlsec1: xml-security: Apache Santuario potentially loads XML parsing code from an untrusted source [fedora-all]
bugzilla·2019-10-23·CVSS 5.5
CVE-2019-12400 [MEDIUM] CVE-2019-12400 xmlsec1: xml-security: Apache Santuario potentially loads XML parsing code from an untrusted source [fedora-all]
CVE-2019-12400 xmlsec1: xml-security: Apache Santuario potentially loads XML parsing code from an untrusted source [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NO
Bugzilla
CVE-2019-12400 xml-security: Apache Santuario potentially loads XML parsing code from an untrusted source [fedora-all]
bugzilla·2019-10-23·CVSS 5.5
CVE-2019-12400 [MEDIUM] CVE-2019-12400 xml-security: Apache Santuario potentially loads XML parsing code from an untrusted source [fedora-all]
CVE-2019-12400 xml-security: Apache Santuario potentially loads XML parsing code from an untrusted source [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
http://santuario.apache.org/secadv.data/CVE-2019-12400.asc?version=1&modificationDate=1566573083000&api=v2https://access.redhat.com/errata/RHSA-2020:0804https://access.redhat.com/errata/RHSA-2020:0805https://access.redhat.com/errata/RHSA-2020:0806https://access.redhat.com/errata/RHSA-2020:0811https://lists.apache.org/thread.html/8e814b925bf580bc527d96ff51e72ffe5bdeaa4b8bf5b89498cab24c%40%3Cdev.santuario.apache.org%3Ehttps://lists.apache.org/thread.html/edaa7edb9c58e5f5bd0c950f2b6232b62b15f5c44ad803e8728308ce%40%3Cdev.santuario.apache.org%3Ehttps://lists.apache.org/thread.html/r107bffb06a5e27457fe9af7dfe3a233d0d36c6c2f5122f117eb7f626%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r1c07a561426ec5579073046ad7f4207cdcef452bb3100abaf908e0cd%40%3Ccommits.santuario.apache.org%3Ehttps://lists.apache.org/thread.html/rcdc0da94fe21b26493eae47ca987a290bdf90c721a7a42491fdd41d4%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/rf82be0a7c98cd3545e20817bb96ed05551ea0020acbaf9a469fef402%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/rf958cea96236de8829940109ae07e870aa3d59235345421e4924ff03%40%3Ccommits.tomee.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20190910-0003/https://www.oracle.com/security-alerts/cpuoct2021.htmlhttp://santuario.apache.org/secadv.data/CVE-2019-12400.asc?version=1&modificationDate=1566573083000&api=v2https://access.redhat.com/errata/RHSA-2020:0804https://access.redhat.com/errata/RHSA-2020:0805https://access.redhat.com/errata/RHSA-2020:0806https://access.redhat.com/errata/RHSA-2020:0811https://lists.apache.org/thread.html/8e814b925bf580bc527d96ff51e72ffe5bdeaa4b8bf5b89498cab24c%40%3Cdev.santuario.apache.org%3Ehttps://lists.apache.org/thread.html/edaa7edb9c58e5f5bd0c950f2b6232b62b15f5c44ad803e8728308ce%40%3Cdev.santuario.apache.org%3Ehttps://lists.apache.org/thread.html/r107bffb06a5e27457fe9af7dfe3a233d0d36c6c2f5122f117eb7f626%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r1c07a561426ec5579073046ad7f4207cdcef452bb3100abaf908e0cd%40%3Ccommits.santuario.apache.org%3Ehttps://lists.apache.org/thread.html/rcdc0da94fe21b26493eae47ca987a290bdf90c721a7a42491fdd41d4%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/rf82be0a7c98cd3545e20817bb96ed05551ea0020acbaf9a469fef402%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/rf958cea96236de8829940109ae07e870aa3d59235345421e4924ff03%40%3Ccommits.tomee.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20190910-0003/https://www.oracle.com/security-alerts/cpuoct2021.html
2019-08-23
Published