imPC@ndo IT

Tracker / CVE-2019-12400

CVE-2019-12400

Medium 5.5

In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread context class loader first, then this implementation might be cached and re-used by Apache Santuario - XML Security for Java, leading to potential security flaws when validating signed documents, etc. The vulnerability affects Apache Santuario - XML Security for Java 2.0.x releases from 2.0.3 and all 2.1.x releases before 2.1.4.

Affected products and versions

apache santuario_xml_security_for_java · 2.0.3 → 2.0.10
apache santuario_xml_security_for_java · 2.1.0 → 2.1.4
oracle weblogic_server
redhat jboss_enterprise_application_platform

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References