{"id":"CVE-2024-34580","details":"Apache XML Security for C++ through 2.0.4 implements the XML Signature Syntax and Processing (XMLDsig) specification without protection against an SSRF payload in a KeyInfo element. NOTE: the project disputes this CVE Record on the grounds that any vulnerabilities are the result of a failure to configure XML Security for C++ securely. Even when avoiding this particular issue, any use of this library would need considerable additional code and a deep understanding of the standards and protocols involved to arrive at a secure implementation for any particular use case. We recommend against continued direct use of this library.","modified":"2024-09-18T03:26:17.298447Z","published":"2024-06-26T05:15:51Z","withdrawn":"2024-08-08T17:18:46Z","references":[{"type":"ARTICLE","url":"https://cloud.google.com/blog/topics/threat-intelligence/apache-library-allows-server-side-request-forgery"},{"type":"ARTICLE","url":"https://www.sonatype.com/blog/the-exploited-ivanti-connect-ssrf-vulnerability-stems-from-xmltooling-oss-library"},{"type":"WEB","url":"https://github.com/zmanion/Vulnerabilities/blob/main/CVE-2024-21893.md"},{"type":"WEB","url":"https://lists.apache.org/thread/po2gocnw4gtf4boy5mmjb54g62qhbrl9"},{"type":"WEB","url":"https://santuario.apache.org/download.html"},{"type":"WEB","url":"https://shibboleth.atlassian.net/wiki/spaces/DEV/pages/3726671873/Santuario"},{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-34580"}],"affected":[{"package":{"name":"xml-security-c","ecosystem":"Debian:11","purl":"pkg:deb/debian/xml-security-c?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.0.2-4","2.0.3-1","2.0.4-1","2.0.4-2","2.0.4-2+hurd.1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-34580.json"}},{"package":{"name":"xml-security-c","ecosystem":"Debian:12","purl":"pkg:deb/debian/xml-security-c?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.0.4-2","2.0.4-2+hurd.1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-34580.json"}},{"package":{"name":"xml-security-c","ecosystem":"Debian:13","purl":"pkg:deb/debian/xml-security-c?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.0.4-2","2.0.4-2+hurd.1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-34580.json"}}],"schema_version":"1.7.3"}