Apache Santuario: Private Key disclosure in debug-log output
Vulnerability Description
All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclosed in log files when generating an XML Signature and logging with debug level is enabled. Users are recommended to upgrade to version 2.2.6, 2.3.4, or 3.0.3, which fixes this issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-44483
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Apache Santuario would like to thank Max Fichtelmann for reporting this issue.
References
More from Apache Software Foundation
View All →Affected Vendor
Apache Software Foundation
View all reports →