CVE EVIDENCE REVIEW
ReviewHighEvidence review

CVE-2021-40690 evidence review

Apache Software Foundation Apache Santuario, santuario xml security for java, cxf

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.

Open CVE record
Evidence review

This record remains available for product and version identification, but it is not presented as a complete remediation procedure. Confirm the affected range and the supported fix in a direct vendor advisory before changing production systems.

ProductApache Software Foundation Apache Santuario, santuario xml security for java, cxf
Affected versions>= XML Security for Java < 2.2.3, 2.1.7, < 2.1.7, >= 2.2.0 < 2.2.3, 3.4.4, < 8.0.8, 9.0, 10.0, 11.0, 9.3.6, 11.3.2, >= 8.0.0 <= 8.1.0, >= 8.2.0 <= 8.2.3, 8.1, 12.1.0, 8.5.5, 8.58, 8.59, 16.0.3, 14.1.3.2, 15.0.3.1
Fixed versions2.1.7, 2.2.3, 8.0.8
Priority basisReview · CVSS 7.5 · EPSS 7.38%
01

Identify the product and installed version

Record whether Apache Software Foundation Apache Santuario, santuario xml security for java, cxf is present, where it is installed, and which interfaces are exposed.

  • Record the product name, package or appliance identifier, and installed version.
  • Identify internet-facing, administrative, API, and internal access paths.
  • Preserve the pre-change configuration and relevant service logs.
02

Compare the affected range

Use the current record as an identification aid: >= XML Security for Java < 2.2.3, 2.1.7, < 2.1.7, >= 2.2.0 < 2.2.3, 3.4.4, < 8.0.8, 9.0, 10.0, 11.0, 9.3.6, 11.3.2, >= 8.0.0 <= 8.1.0, >= 8.2.0 <= 8.2.3, 8.1, 12.1.0, 8.5.5, 8.58, 8.59, 16.0.3, 14.1.3.2, 15.0.3.1. Resolve incomplete inventory results before deciding that an asset is unaffected.

03

Verify the authoritative remediation source

Open the linked source material and locate a direct vendor advisory for this CVE. Confirm the supported fixed release and product-specific update path before making a production change.

Operational boundary

This page does not replace the vendor advisory, support contract, change-management process, or recovery plan. Do not infer that an asset is unaffected from an incomplete inventory query or a missing fixed-version field.