Insertion of Sensitive Information into Log File Affecting org.apache.santuario:xmlsec package, versions [,2.2.6) [2.3.0,2.3.4) [3.0.0,3.0.3)
Threat Intelligence
EPSS
0.1% (43rd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JAVA-ORGAPACHESANTUARIO-6017551
- published 20 Oct 2023
- disclosed 20 Oct 2023
- credit Max Fichtelmann
Introduced: 20 Oct 2023
CVE-2023-44483 Open this link in a new tabHow to fix?
Upgrade org.apache.santuario:xmlsec
to version 2.2.6, 2.3.4, 3.0.3 or higher.
Overview
org.apache.santuario:xmlsec is a package to provide implementation of the primary security standards for XML, XML-Signature Syntax and Processing and XML Encryption Syntax and Processing.
Affected versions of this package are vulnerable to Insertion of Sensitive Information into Log File when using the JSR 105 API. An attacker can disclose a private key in log files by generating an XML Signature and enabling logging with debug level.
References
CVSS Scores
version 3.1