CVE-2023-44483
Last modified
CVE-2023-44483 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclosed in log files when generating an XML Signature and logging with debug level is enabled. Users are recommended to upgrade to version 2.2.6, 2.3.4, or 3.0.3, which fixes this issue.. EPSS estimates a 1.21% chance of exploitation in the next 30 days.
Description
All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclosed in log files when generating an XML Signature and logging with debug level is enabled. Users are recommended to upgrade to version 2.2.6, 2.3.4, or 3.0.3, which fixes this issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Santuario Xml Security For Java | < 2.2.6 |
| Apache | Santuario Xml Security For Java | >= 2.3.0, < 2.3.4 |
| Apache | Santuario Xml Security For Java | >= 3.0.0, < 3.0.3 |
References
- http://www.openwall.com/lists/oss-security/2023/10/20/5Mailing List, Third Party Advisory
- https://lists.apache.org/thread/vmqbp9mfxtrf0kmbnnmbn3h9j6dr9q55Mailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2023/10/20/5Mailing List, Third Party Advisory
- https://lists.apache.org/thread/vmqbp9mfxtrf0kmbnnmbn3h9j6dr9q55Mailing List, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-44483?
How severe is CVE-2023-44483?
How do I fix CVE-2023-44483?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-44478Cross-Site Request Forgery (CSRF) vulnerability in WP Hive E…7.1
- CVE-2023-44479Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerabili…4.8
- CVE-2023-4448A vulnerability was found in OpenRapid RapidCMS 1.3.1 and cl…9.8
- CVE-2023-44480Leave Management System Project v1.0 is vulnerable to multip…8.8
- CVE-2023-44481Leave Management System Project v1.0 is vulnerable to multip…8.8
- CVE-2023-44482Leave Management System Project v1.0 is vulnerable to multip…8.8
- CVE-2023-44484Online Blood Donation Management System v1.0 is vulnerable t…6.1
- CVE-2023-44485Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2023-44486Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2023-44487The HTTP/2 protocol allows a denial of service (server resou…7.5
- CVE-2023-44488VP9 in libvpx before 1.13.1 mishandles widths, leading to a …7.5
- CVE-2023-4449A vulnerability was found in SourceCodester Free and Open So…8.8
Are you affected by CVE-2023-44483?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
