XML Signature Spoofing in Apache Santuario XML Security for Java
CVE-2013-2172

Currently unrated

Key Information:

Vendor
Apache
Vendor
CVE Published:
20 August 2013

Summary

The vulnerability in Apache Santuario XML Security for Java is caused by the ability for context-dependent attackers to spoof an XML Signature. This is achieved through a flaw in the CanonicalizationMethod parameter, which allows an attacker to specify a weak canonicalization algorithm for the SignedInfo part of the Signature. As a result, the integrity and authenticity of XML documents can be compromised, leading to potential security breaches and exploitation of sensitive data.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.