CVE-2013-2172: Apache Santuario XML Security For Java
Medium severity, CVSS 4.3. EPSS: 5.9% chance of exploitation in the next 30 days.
jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to specify an arbitrary weak "canonicalization algorithm to apply to the SignedInfo part of the Signature."
Affected products
- Apache Santuario XML Security For Java: version 1.4.7 only; version 1.5.0 only; version 1.5.1 only; version 1.5.2 only; version 1.5.3 only; version 1.5.4 only
Published 2013-08-20. Last modified 2026-06-16.