USN-5525-1

See a problem?
Source
https://ubuntu.com/security/notices/USN-5525-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/USN-5525-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-5525-1
Related
Published
2022-07-20T10:47:58.468512Z
Modified
2022-07-20T10:47:58.468512Z
Summary
libxml-security-java vulnerability
Details

It was discovered that Apache XML Security for Java incorrectly passed a configuration property when creating specific key elements. This allows an attacker to abuse an XPath Transform to extract sensitive information.

References

Affected packages

Ubuntu:20.04:LTS / libxml-security-java

Package

Name
libxml-security-java

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.10-2+deb11u1build0.20.04.1

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "libxml-security-java": "2.0.10-2+deb11u1build0.20.04.1",
            "libxml-security-java-doc": "2.0.10-2+deb11u1build0.20.04.1"
        }
    ]
}

Ubuntu:18.04:LTS / libxml-security-java

Package

Name
libxml-security-java

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.10-2~18.04.1

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "libxml-security-java": "2.0.10-2~18.04.1",
            "libxml-security-java-doc": "2.0.10-2~18.04.1"
        }
    ]
}