Web Hack List

Collected research

Ping'ing XMLSec

Apache Santuario dereferences URIs in KeyInfoReference and RetrievalMethod elements before any signature check, and fails to pass its secureValidation flag down, so an unauthenticated attacker can make it read local files and then apply XPath or XSLT transforms to them.

Record

Published by
blog.tint0.com
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of blog.tint0.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .