
Cloud Vulnerability DB
A community-led vulnerabilities database
All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to a private key disclosure issue. The vulnerability was discovered and reported by Max Fichtelmann, and was assigned CVE-2023-44483 (NVD, Apache Advisory).
The vulnerability occurs when generating an XML Signature with debug level logging enabled. Under these conditions, private key information may be exposed in log files. The issue has been assigned a CVSS v3.1 base score of 6.5 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N. The vulnerability is classified as CWE-532: Insertion of Sensitive Information into Log File (NVD).
The vulnerability could lead to the disclosure of private key information in log files, potentially compromising the security of XML signatures generated using the affected versions. This exposure could allow attackers to gain access to sensitive cryptographic material (OSS Security).
Users are recommended to upgrade to Apache Santuario versions 2.2.6, 2.3.4, or 3.0.3, which contain fixes for this vulnerability. These versions have been released specifically to address the private key disclosure issue (Apache Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."