XML Signature Spoofing in Apache Santuario XML Security for Java
CVE-2013-2172

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
20 August 2013

What is CVE-2013-2172?

The vulnerability in Apache Santuario XML Security for Java is caused by the ability for context-dependent attackers to spoof an XML Signature. This is achieved through a flaw in the CanonicalizationMethod parameter, which allows an attacker to specify a weak canonicalization algorithm for the SignedInfo part of the Signature. As a result, the integrity and authenticity of XML documents can be compromised, leading to potential security breaches and exploitation of sensitive data.

References

EPSS Score

6% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2013-2172 : XML Signature Spoofing in Apache Santuario XML Security for Java