CVE-2013-2172
Last modified
CVE-2013-2172 is a vulnerability of currently unknown severity. jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to specify an arbitrary weak "canonicalization algorithm to apply to the SignedInfo part of the Signature.". EPSS estimates a 5.93% chance of exploitation in the next 30 days.
Description
jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to specify an arbitrary weak "canonicalization algorithm to apply to the SignedInfo part of the Signature."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Santuario Xml Security For Java | 1.4.7 |
| Apache | Santuario Xml Security For Java | 1.5.0 |
| Apache | Santuario Xml Security For Java | 1.5.1 |
| Apache | Santuario Xml Security For Java | 1.5.2 |
| Apache | Santuario Xml Security For Java | 1.5.3 |
| Apache | Santuario Xml Security For Java | 1.5.4 |
References
- http://secunia.com/advisories/54019Vendor Advisory
- http://secunia.com/advisories/54019Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-2172?
How severe is CVE-2013-2172?
How do I fix CVE-2013-2172?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-2166python-keystoneclient version 0.2.3 to 0.2.5 has middleware …9.8
- CVE-2013-2167python-keystoneclient version 0.2.3 to 0.2.5 has middleware …9.8
- CVE-2013-2168The _dbus_printf_string_upper_bound function in dbus/dbus-sy…
- CVE-2013-2169Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2013-2170Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2013-2171The vm_map_lookup function in sys/vm/vm_map.c in the mmap im…
- CVE-2013-2173wp-includes/class-phpass.php in WordPress 3.5.1, when a pass…
- CVE-2013-2174Heap-based buffer overflow in the curl_easy_unescape functio…
- CVE-2013-2175HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when con…
- CVE-2013-2176Unquoted Windows search path vulnerability in the Red Hat En…
- CVE-2013-2177Cross-site scripting (XSS) vulnerability in the Display Suit…
- CVE-2013-2178The apache-auth.conf, apache-nohome.conf, apache-noscript.co…
Are you affected by CVE-2013-2172?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
