Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-44483


All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclosed in log files when generating an XML Signature and logging with debug level is enabled. Users are recommended to upgrade to version 2.2.6, 2.3.4, or 3.0.3, which fixes this issue.


Published

2023-10-20T10:15:12.933

Last Modified

2025-02-13T17:17:14.313

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-532

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache santuario_xml_security_for_java < 2.2.6 Yes
Application apache santuario_xml_security_for_java < 2.3.4 Yes
Application apache santuario_xml_security_for_java < 3.0.3 Yes

References