CVE-2021-40690
published 2021-09-19CVE-2021-40690: All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not…
PriorityP354high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
11.21%
95.5th percentile
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cxf | — | — |
| apache | santuario_xml_security_for_java | < 2.1.7 | 2.1.7 |
| apache | santuario_xml_security_for_java | >= 2.2.0 < 2.2.3 | 2.2.3 |
| apache | tomee | < 8.0.8 | 8.0.8 |
| apache_software_foundation | apache_santuario | >= XML Security for Java < 2.2.3,2.1.7 | 2.2.3,2.1.7 |
| atlassian | crowd | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libxml-security-java | < libxml-security-java 2.1.7-1 (bookworm) | libxml-security-java 2.1.7-1 (bookworm) |
| oracle | agile_plm | — | — |
| oracle | commerce_guided_search | — | — |
| oracle | commerce_platform | — | — |
| oracle | communications_diameter_intelligence_hub | 8.0.0 – 8.1.0 | — |
| oracle | communications_diameter_intelligence_hub | 8.2.0 – 8.2.3 | — |
| oracle | communications_messaging_server | — | — |
| oracle | flexcube_private_banking | — | — |
| oracle | outside_in_technology | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | retail_bulk_data_integration | — | — |
| oracle | retail_financial_integration | — | — |
| oracle | retail_financial_integration | — | — |
| oracle | retail_financial_integration | — | — |
| oracle | retail_financial_integration | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Atlassian
CVE-2021-40690: Info Disclosure org.apache.santuario:xmlsec Dependency in Crowd Data Center and Server
vendor_atlassian·2024-01-16·CVSS 7.5
CVE-2021-40690 [HIGH] CVE-2021-40690: Info Disclosure org.apache.santuario:xmlsec Dependency in Crowd Data Center and Server
CVE-2021-40690: Info Disclosure org.apache.santuario:xmlsec Dependency in Crowd Data Center and Server
Info Disclosure org.apache.santuario:xmlsec Dependency in Crowd Data Center and Server
CVE: CVE-2021-40690
Severity: HIGH
Affected products: Crowd
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: PSEM Plugin (Apache Santuario XML Security For Java) — CVE-2021-40690
vendor_oracle·2023-10-15·CVSS 7.5
CVE-2021-40690 [HIGH] Oracle Oracle Enterprise Manager Risk Matrix: PSEM Plugin (Apache Santuario XML Security For Java) — CVE-2021-40690
Oracle Oracle Enterprise Manager Risk Matrix: PSEM Plugin (Apache Santuario XML Security For Java) vulnerability
CVE: CVE-2021-40690
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Oracle
Oracle Oracle Commerce Risk Matrix: Endeca Application Controller (Apache Santuario XML Security For Java) — CVE-2021-40690
vendor_oracle·2023-07-15·CVSS 7.5
CVE-2021-40690 [HIGH] Oracle Oracle Commerce Risk Matrix: Endeca Application Controller (Apache Santuario XML Security For Java) — CVE-2021-40690
Oracle Oracle Commerce Risk Matrix: Endeca Application Controller (Apache Santuario XML Security For Java) vulnerability
CVE: CVE-2021-40690
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Apache Santuario XML Security For Java) — CVE-2021-40690
vendor_oracle·2023-04-15·CVSS 7.5
CVE-2021-40690 [HIGH] Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Apache Santuario XML Security For Java) — CVE-2021-40690
Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Apache Santuario XML Security For Java) vulnerability
CVE: CVE-2021-40690
CVSS: 7.5
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Communications Risk Matrix: OAuth (Apache Santuario XML Security for Java) — CVE-2021-40690
vendor_oracle·2022-10-15·CVSS 7.5
CVE-2021-40690 [HIGH] Oracle Oracle Communications Risk Matrix: OAuth (Apache Santuario XML Security for Java) — CVE-2021-40690
Oracle Oracle Communications Risk Matrix: OAuth (Apache Santuario XML Security for Java) vulnerability
CVE: CVE-2021-40690
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Ubuntu
Apache XML Security for Java vulnerability
vendor_ubuntu·2022-07-20
CVE-2021-40690 Apache XML Security for Java vulnerability
Title: Apache XML Security for Java vulnerability
Summary: Apache XML Security for Java could be made to expose sensitive information.
It was discovered that Apache XML Security for Java incorrectly passed a
configuration property when creating specific key elements. This allows an
attacker to abuse an XPath Transform to extract sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Commerce Risk Matrix: Content Acquisition System (Apache CXF) — CVE-2021-40690
vendor_oracle·2022-07-15·CVSS 7.5
CVE-2021-40690 [HIGH] Oracle Oracle Commerce Risk Matrix: Content Acquisition System (Apache CXF) — CVE-2021-40690
Oracle Oracle Commerce Risk Matrix: Content Acquisition System (Apache CXF) vulnerability
CVE: CVE-2021-40690
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Communications Applications Risk Matrix: ISC (Apache Santuario XML Security For Java) — CVE-2021-40690
vendor_oracle·2022-04-15·CVSS 7.5
CVE-2021-40690 [HIGH] Oracle Oracle Communications Applications Risk Matrix: ISC (Apache Santuario XML Security For Java) — CVE-2021-40690
Oracle Oracle Communications Applications Risk Matrix: ISC (Apache Santuario XML Security For Java) vulnerability
CVE: CVE-2021-40690
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Red Hat
xml-security: XPath Transform abuse allows for information disclosure
vendor_redhat·2021-09-17·CVSS 7.5
CVE-2021-40690 [HIGH] CWE-200 xml-security: XPath Transform abuse allows for information disclosure
xml-security: XPath Transform abuse allows for information disclosure
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
Statement: Since OpenShift Container Platform (OCP) 4.7, the logging-elasticsearch6-container is shipping as a part of the OpenShift Logging product (openshift-logging/elasticsearch6-rhel8). The elasticsearch component delivered in OCP 4.6 is marked as `Out of support scope` because these versions are already under Maintenance Phase of the support.
Package: openshift-logging/elastic
Debian
CVE-2021-40690: libxml-security-java - All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1....
vendor_debian·2021·CVSS 7.5
CVE-2021-40690 [HIGH] CVE-2021-40690: libxml-security-java - All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1....
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
Scope: local
bookworm: resolved (fixed in 2.1.7-1)
bullseye: resolved (fixed in 2.0.10-2+deb11u1)
forky: resolved (fixed in 2.1.7-1)
sid: resolved (fixed in 2.1.7-1)
trixie: resolved (fixed in 2.1.7-1)
OSV
Exposure of Sensitive Information to an Unauthorized Actor in Apache Santuario
osv·2021-09-20
CVE-2021-40690 [HIGH] Exposure of Sensitive Information to an Unauthorized Actor in Apache Santuario
Exposure of Sensitive Information to an Unauthorized Actor in Apache Santuario
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in Apache Santuario
ghsa·2021-09-20
CVE-2021-40690 [HIGH] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Apache Santuario
Exposure of Sensitive Information to an Unauthorized Actor in Apache Santuario
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
OSV
CVE-2021-40690: All versions of Apache Santuario - XML Security for Java prior to 2
osv·2021-09-19·CVSS 7.5
CVE-2021-40690 [HIGH] CVE-2021-40690: All versions of Apache Santuario - XML Security for Java prior to 2
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
No detection rules found.
No public exploits indexed.
https://lists.apache.org/thread.html/r3b3f5ba9b0de8c9c125077b71af06026d344a709a8ba67db81ee9faa%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r401ecb7274794f040cd757b259ebe3e8c463ae74f7961209ccad3c59%40%3Cissues.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/r8848751b6a5dd78cc9e99d627e74fecfaffdfa1bb615dce827aad633%40%3Cdev.santuario.apache.org%3Ehttps://lists.apache.org/thread.html/r8a5c0ce9014bd07303aec1e5eed55951704878016465d3dae00e0c28%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r9c100d53c84d54cf71975e3f0cfcc2856a8846554a04c99390156ce4%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/raf352f95c19c0c4051af3180752cb69acbea88d0d066ab176c6170e8%40%3Cuser.poi.apache.org%3Ehttps://lists.apache.org/thread.html/rbbbac0759b12472abd0c278d32b5e0867bb21934df8e14e5e641597c%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/rbdac116aef912b563da54f4c152222c0754e32fb2f785519ac5e059f%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/re294cfc61f509512874ea514d8d64fd276253d54ac378ffa7a4880c8%40%3Ccommits.tomee.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/09/msg00015.htmlhttps://security.netapp.com/advisory/ntap-20230818-0002/https://www.debian.org/security/2021/dsa-5010https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://lists.apache.org/thread.html/r3b3f5ba9b0de8c9c125077b71af06026d344a709a8ba67db81ee9faa%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r401ecb7274794f040cd757b259ebe3e8c463ae74f7961209ccad3c59%40%3Cissues.cxf.apache.org%3Ehttps://lists.apache.org/thread.html/r8848751b6a5dd78cc9e99d627e74fecfaffdfa1bb615dce827aad633%40%3Cdev.santuario.apache.org%3Ehttps://lists.apache.org/thread.html/r8a5c0ce9014bd07303aec1e5eed55951704878016465d3dae00e0c28%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r9c100d53c84d54cf71975e3f0cfcc2856a8846554a04c99390156ce4%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/raf352f95c19c0c4051af3180752cb69acbea88d0d066ab176c6170e8%40%3Cuser.poi.apache.org%3Ehttps://lists.apache.org/thread.html/rbbbac0759b12472abd0c278d32b5e0867bb21934df8e14e5e641597c%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/rbdac116aef912b563da54f4c152222c0754e32fb2f785519ac5e059f%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/re294cfc61f509512874ea514d8d64fd276253d54ac378ffa7a4880c8%40%3Ccommits.tomee.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/09/msg00015.htmlhttps://security.netapp.com/advisory/ntap-20230818-0002/https://www.debian.org/security/2021/dsa-5010https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2021-09-19
Published