CVE-2013-2172 REJECTED

jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to specify an arbitrary weak "canonicalization algorithm to apply to the SignedInfo part of the Signature."

EPSS 5.39% · 90.1th percentile

Risk Scores

EPSS Score
5.39%
90.1th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlibxml-security-java0

Timeline

References

Open in Interactive Console →