VDB
DEBIAN-CVE-2021-40690
DEBIAN-CVE-2021-40690
PUBLISHED
CVSS 7.5 HIGH
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:12 | libxml-security-java | 0, 0, 0 |
| Debian:14 | libxml-security-java | 0, 0, 0 |
| Debian:13 | libxml-security-java | 0, 0, 0 |
| Debian:11 | libxml-security-java | 0, 2.0.10-2, 0 |
Timeline
- Sep 19, 2021 CVE Published
- Apr 28, 2026 CVE Updated