ReviewHigh

CVE-2021-40690

Apache Software Foundation Apache Santuario, santuario xml security for java, cxf

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.

CVSS
7.5
EPSS
7.38%
94.0% percentile
CISA KEV
Not listed
Published
2021.09.20
PRIORITY ASSESSMENT

Review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability7.38%
Technical severityCVSS 7.5

Vulnerability overview

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.

Affected product and versions

Product
Apache Software Foundation Apache Santuario, santuario xml security for java, cxf
Affected versions
>= XML Security for Java < 2.2.3, 2.1.7, < 2.1.7, >= 2.2.0 < 2.2.3, 3.4.4, < 8.0.8, 9.0, 10.0, 11.0, 9.3.6, 11.3.2, >= 8.0.0 <= 8.1.0, >= 8.2.0 <= 8.2.3, 8.1, 12.1.0, 8.5.5, 8.58, 8.59, 16.0.3, 14.1.3.2, 15.0.3.1
Fixed versions
2.1.7, 2.2.3, 8.0.8

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Apache Software Foundation Apache Santuario, santuario xml security for java, cxf and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE
CWE-200