XML Parsing Vulnerability in Apache Santuario XML Security for Java
CVE-2019-12400
Key Information:
- Vendor
Apache
- Vendor
- CVE Published:
- 23 August 2019
What is CVE-2019-12400?
In versions of Apache Santuario XML Security for Java starting from 2.0.3, a caching mechanism was implemented to optimize the creation of new XML documents using a static pool of DocumentBuilders. However, this mechanism is susceptible to risks if untrusted code registers a harmful implementation with the thread context class loader. Consequently, the cached implementation may be reused by the library, leading to potential security issues, particularly during the validation of signed documents. Versions affected by this vulnerability include 2.0.x from 2.0.3 and all 2.1.x releases prior to version 2.1.4.
Affected Version(s)
Apache Santuario - XML Security for Java All 2.0.x releases from 2.0.3
Apache Santuario - XML Security for Java all 2.1.x releases before 2.1.4.