VDB
Sign up
MEDIUM

GHSA-8gwc-x7mg-7p7p

Apache XML Security For Java vulnerable to Infinite Loop

Quick fix

GHSA-8gwc-x7mg-7p7p — org.apache.santuario:xmlsec: upgrade to the fixed version with the command below.

# pom.xml: bump <version>1.4.8</version> for org.apache.santuario:xmlsec

Details

Affected versions of xmlsec are subject to a denial of service vulnerability. Should a user check the signature of a message larger than 512 MB, the method `expandSize(int newPos)` of class `org.apache.xml.security.utils.UnsyncByteArrayOutputStream` goes in an endless loop. A remote attacker could use this flaw to supply crafted XML that would lead to a denial of service.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.santuario:xmlsec
Introduced in: 1.4.0Fixed in: 1.4.8
Fix# pom.xml: bump <version>1.4.8</version> for org.apache.santuario:xmlsec
Maven/org.apache.santuario:xmlsec
Introduced in: 1.5.0Fixed in: 1.5.3
Fix# pom.xml: bump <version>1.5.3</version> for org.apache.santuario:xmlsec

References