← back
CVE-2023-49087

Validation of SignedInfo

CVSS 6.8 MEDIUMEPSS 0.2%CWE-345
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.8EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
30 Nov 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
xml-security is a library that implements XML signatures and encryption. Validation of an XML signature requires verification that the hash value of the related XML-document matches a specific DigestValue-value, but also that the cryptographic signature on the SignedInfo-tree (the one that contains the DigestValue) verifies and matches a trusted public key. If an attacker somehow (i.e. by exploiting a bug in PHP's canonicalization function) manages to manipulate the canonicalized version's DigestValue, it would be possible to forge the signature. This issue has been patched in version 1.6.12 and 5.0.0-alpha.13.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →