VDB
CVE-2019-12400
CVE-2019-12400
PUBLISHED
In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread context class loader first, then this implementation might be cached and re-used by Apache Santuario - XML Security for Java, leading to potential security flaws when validating signed documents, etc. The vulnerability affects Apache Santuario - XML Security for Java 2.0.x releases from 2.0.3 and all 2.1.x releases before 2.1.4.
EPSS 0.59% · 69.5th percentile
Risk Scores
EPSS Score
0.59%
69.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:20.04:LTS | libxml-security-java | 0, 2.0.10-2, 2.0.10-2+deb11u1build0.20.04.1 |
| Ubuntu:16.04:LTS | libxml-security-java | 1.5.6-1, 0 |
| Ubuntu:18.04:LTS | libxml-security-java | 2.0.10-2~18.04.1, 1.5.8-2, 0 |
Timeline
- Aug 23, 2019 CVE Published
- Sep 19, 2019 CVE Updated
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 21, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-12400 third-party-advisory
- http://santuario.apache.org/secadv.data/CVE-2019-12400.asc third-party-advisory
- http://santuario.apache.org/secadv.data/CVE-2019-12400.asc?version=1&modificationDate=1566573083000&api=v2 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-12400 third-party-advisory