XML Signature Spoofing in Apache Santuario XML Security for Java
CVE-2013-2172
Currently unrated
Key Information:
- Vendor
- Apache
- Vendor
- CVE Published:
- 20 August 2013
Summary
The vulnerability in Apache Santuario XML Security for Java is caused by the ability for context-dependent attackers to spoof an XML Signature. This is achieved through a flaw in the CanonicalizationMethod parameter, which allows an attacker to specify a weak canonicalization algorithm for the SignedInfo part of the Signature. As a result, the integrity and authenticity of XML documents can be compromised, leading to potential security breaches and exploitation of sensitive data.
References
Timeline
Vulnerability published
Vulnerability Reserved