Loading HuntDB...

GHSA-j8wc-gxx9-82hx

GitHub Security Advisory

Exposure of Sensitive Information to an Unauthorized Actor in Apache Santuario

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.

Affected Packages

Maven org.apache.santuario:xmlsec
Affected versions: 2.2.0 (fixed in 2.2.3)
Maven org.apache.santuario:xmlsec
Affected versions: 0 (fixed in 2.1.7)

Related CVEs

Key Information

GHSA ID
GHSA-j8wc-gxx9-82hx
Published
September 20, 2021 11:18 PM
Last Modified
October 4, 2021 2:16 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.apache.santuario:xmlsec
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 28, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.