Total vulnerabilities in the database
jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to specify an arbitrary weak "canonicalization algorithm to apply to the SignedInfo part of the Signature."
Software | From | Fixed in |
---|---|---|
![]() |
1.4.0 | 1.4.8 |
![]() |
1.5.0 | 1.5.5 |
apache / santuario_xml_security_for_java | 1.5.1 | 1.5.1.x |
apache / santuario_xml_security_for_java | 1.5.2 | 1.5.2.x |
apache / santuario_xml_security_for_java | 1.5.4 | 1.5.4.x |
apache / santuario_xml_security_for_java | 1.5.3 | 1.5.3.x |
apache / santuario_xml_security_for_java | 1.4.7 | 1.4.7.x |
apache / santuario_xml_security_for_java | 1.5.0 | 1.5.0.x |