漏洞信息详情
Apache Santuario 信息泄露漏洞
漏洞简介
Apache Santuario是美国阿帕奇(Apache)基金会的一套实现XML的主要安全标准,它包含两个库:Apache XML Security for Java和Apache XML Security for C++。
Apache Santuario XML Security for Java存在信息泄露漏洞,该漏洞源于软件中的Keyinfo SecureValidation Xpath Transform缺少有效验证。攻击者可利用该漏洞通过该字段读取文件,以获取敏感信息。
漏洞公告
目前厂商暂未发布修复措施解决此安全问题,建议使用此软件的用户随时关注厂商主页或参考网址以获取解决办法:
https://santuario.apache.org/javaindex.html
参考网址
来源:MLIST
链接:https://lists.apache.org/thread.html/re294cfc61f509512874ea514d8d64fd276253d54ac378ffa7a4880c8@%3Ccommits.tomee.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/raf352f95c19c0c4051af3180752cb69acbea88d0d066ab176c6170e8@%3Cuser.poi.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/rbbbac0759b12472abd0c278d32b5e0867bb21934df8e14e5e641597c@%3Ccommits.tomee.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/r3b3f5ba9b0de8c9c125077b71af06026d344a709a8ba67db81ee9faa@%3Ccommits.tomee.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/rbdac116aef912b563da54f4c152222c0754e32fb2f785519ac5e059f@%3Ccommits.tomee.apache.org%3E
来源:DEBIAN
链接:https://www.debian.org/security/2021/dsa-5010
来源:MLIST
链接:https://lists.apache.org/thread.html/r9c100d53c84d54cf71975e3f0cfcc2856a8846554a04c99390156ce4@%3Ccommits.tomee.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/r401ecb7274794f040cd757b259ebe3e8c463ae74f7961209ccad3c59@%3Cissues.cxf.apache.org%3E
来源:MISC
链接:https://lists.apache.org/thread.html/r8848751b6a5dd78cc9e99d627e74fecfaffdfa1bb615dce827aad633%40%3Cdev.santuario.apache.org%3E
来源:MLIST
链接:https://lists.apache.org/thread.html/r8a5c0ce9014bd07303aec1e5eed55951704878016465d3dae00e0c28@%3Ccommits.tomee.apache.org%3E
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2021/09/msg00015.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3893
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3230
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6519472
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Apache-Santuario-XML-Security-for-Java-file-reading-via-KeyInfo-SecureValidation-XPath-Transform-36452
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021111712
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-40690
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021111622
受影响实体
暂无
补丁
暂无
还没有评论,来说两句吧...