Uploaded image for project: 'mod-login-saml'
  1. mod-login-saml
  2. MODLOGSAML-137

secureValidation vulnerability (CVE-2021-40690)

    XMLWordPrintable

Details

    • Bug
    • Status: Closed (View Workflow)
    • TBD
    • Resolution: Done
    • None
    • 2.4.4
    • CP: sprint 137
    • 1
    • Core: Platform
    • TBD

    Description

      pac4j ships with org.apache.santuario:xmlsec@2.1.6 that contains a secureValidation XML vulnerability: https://nvd.nist.gov/vuln/detail/CVE-2021-40690

      Until a fixed vertx-pac4j and pac4j version is available we need to manually upgrade xmlsec.

      TestRail: Results

        Attachments

          Activity

            People

              julianladisch Julian Ladisch
              julianladisch Julian Ladisch
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                TestRail: Runs

                  TestRail: Cases