CVE-2021-40690 | All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
- 🔗 lists.apache.org/thread.html/r8848751b6a5dd78cc9e99d627e74…
- 🔗 lists.apache.org/thread.html/rbdac116aef912b563da54f4c1522…
- 🔗 lists.apache.org/thread.html/re294cfc61f509512874ea514d8d6…
- 🔗 lists.apache.org/thread.html/r8a5c0ce9014bd07303aec1e5eed5…
- 🔗 lists.apache.org/thread.html/r9c100d53c84d54cf71975e3f0cfc…
- 🔗 lists.apache.org/thread.html/r3b3f5ba9b0de8c9c125077b71af0…
- 🔗 lists.apache.org/thread.html/raf352f95c19c0c4051af3180752c…
- 🔗 lists.debian.org/debian-lts-announce/2021/09/msg00015.html
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-06 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2021-40690 | All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows