{"id":"CVE-2021-40690","title":"All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the \"secureValidation\" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element","summary":"All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the \"secureValidation\" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allo…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-200"],"vendor":"apache","product":"santuario_xml_security_for_java","affected":["santuario_xml_security_for_java < 2.1.7","santuario_xml_security_for_java >= 2.2.0, < 2.2.3","cxf = 3.4.4","tomee < 8.0.8","debian_linux = 9.0","debian_linux = 10.0","debian_linux = 11.0","agile_product_lifecycle_management = 9.3.6","commerce_guided_search = 11.3.2","commerce_platform = 11.3.2","communications_diameter_intelligence_hub >= 8.0.0, <= 8.1.0","communications_diameter_intelligence_hub >= 8.2.0, <= 8.2.3","communications_messaging_server = 8.1","flexcube_private_banking = 12.1.0","outside_in_technology = 8.5.5","peoplesoft_enterprise_peopletools = 8.58","peoplesoft_enterprise_peopletools = 8.59","retail_bulk_data_integration = 16.0.3","retail_financial_integration = 14.1.3.2","retail_financial_integration = 15.0.3.1","retail_financial_integration = 16.0.3","retail_financial_integration = 19.0.1","retail_integration_bus = 14.1.3.2","retail_integration_bus = 15.0.3.1","retail_integration_bus = 16.0.3","retail_integration_bus = 19.0.1","retail_merchandising_system = 16.0.3","retail_merchandising_system = 19.0.1","retail_service_backbone = 14.1.3.2","retail_service_backbone = 15.0.3.1","retail_service_backbone = 16.0.3","retail_service_backbone = 19.0.1","weblogic_server = 12.2.1.4.0","weblogic_server = 14.1.1.0.0"],"patched":["santuario_xml_security_for_java 2.2.3","tomee 8.0.8"],"published":"2021-09-19","updated":"2026-08-25","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-40690","references":[{"url":"https://lists.apache.org/thread.html/r3b3f5ba9b0de8c9c125077b71af06026d344a709a8ba67db81ee9faa%40%3Ccommits.tomee.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r401ecb7274794f040cd757b259ebe3e8c463ae74f7961209ccad3c59%40%3Cissues.cxf.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r8848751b6a5dd78cc9e99d627e74fecfaffdfa1bb615dce827aad633%40%3Cdev.santuario.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r8a5c0ce9014bd07303aec1e5eed55951704878016465d3dae00e0c28%40%3Ccommits.tomee.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r9c100d53c84d54cf71975e3f0cfcc2856a8846554a04c99390156ce4%40%3Ccommits.tomee.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/raf352f95c19c0c4051af3180752cb69acbea88d0d066ab176c6170e8%40%3Cuser.poi.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rbbbac0759b12472abd0c278d32b5e0867bb21934df8e14e5e641597c%40%3Ccommits.tomee.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rbdac116aef912b563da54f4c152222c0754e32fb2f785519ac5e059f%40%3Ccommits.tomee.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/re294cfc61f509512874ea514d8d64fd276253d54ac378ffa7a4880c8%40%3Ccommits.tomee.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.debian.org/debian-lts-announce/2021/09/msg00015.html","label":"security@apache.org"},{"url":"https://security.netapp.com/advisory/ntap-20230818-0002/","label":"security@apache.org"},{"url":"https://www.debian.org/security/2021/dsa-5010","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r3b3f5ba9b0de8c9c125077b71af06026d344a709a8ba67db81ee9faa%40%3Ccommits.tomee.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r401ecb7274794f040cd757b259ebe3e8c463ae74f7961209ccad3c59%40%3Cissues.cxf.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r8848751b6a5dd78cc9e99d627e74fecfaffdfa1bb615dce827aad633%40%3Cdev.santuario.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r8a5c0ce9014bd07303aec1e5eed55951704878016465d3dae00e0c28%40%3Ccommits.tomee.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r9c100d53c84d54cf71975e3f0cfcc2856a8846554a04c99390156ce4%40%3Ccommits.tomee.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/raf352f95c19c0c4051af3180752cb69acbea88d0d066ab176c6170e8%40%3Cuser.poi.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rbbbac0759b12472abd0c278d32b5e0867bb21934df8e14e5e641597c%40%3Ccommits.tomee.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rbdac116aef912b563da54f4c152222c0754e32fb2f785519ac5e059f%40%3Ccommits.tomee.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/re294cfc61f509512874ea514d8d64fd276253d54ac378ffa7a4880c8%40%3Ccommits.tomee.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2021/09/msg00015.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20230818-0002/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2021/dsa-5010","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-40690.json"},{"url":"https://access.redhat.com/security/cve/CVE-2021-40690"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2011190"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-40690"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-40690"},{"url":"https://access.redhat.com/errata/RHSA-2021:5149"},{"url":"https://access.redhat.com/errata/RHSA-2025:4226"},{"url":"https://access.redhat.com/errata/RHSA-2021:5150"},{"url":"https://access.redhat.com/errata/RHSA-2022:0151"},{"url":"https://access.redhat.com/errata/RHSA-2021:5151"},{"url":"https://access.redhat.com/errata/RHSA-2022:0164"},{"url":"https://access.redhat.com/errata/RHSA-2022:0152"},{"url":"https://access.redhat.com/errata/RHSA-2021:5154"},{"url":"https://access.redhat.com/errata/RHSA-2022:6407"},{"url":"https://access.redhat.com/errata/RHSA-2022:1013"},{"url":"https://access.redhat.com/errata/RHSA-2022:0501"},{"url":"https://access.redhat.com/errata/RHSA-2022:0155"},{"url":"https://access.redhat.com/errata/RHSA-2022:0146"},{"url":"https://access.redhat.com/errata/RHSA-2022:5532"},{"url":"https://access.redhat.com/errata/RHSA-2021:4679"},{"url":"https://access.redhat.com/errata/RHSA-2021:5170"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.0738,"epssPercentile":0.94142,"ingestedAt":"2026-08-25T17:29:31.440Z","slug":"CVE-2021-40690","body":"## Overview\n\nAll versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the \"secureValidation\" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.\n\n## Affected\n\n- `santuario_xml_security_for_java < 2.1.7`\n- `santuario_xml_security_for_java >= 2.2.0, < 2.2.3`\n- `cxf = 3.4.4`\n- `tomee < 8.0.8`\n- `debian_linux = 9.0`\n- `debian_linux = 10.0`\n- `debian_linux = 11.0`\n- `agile_product_lifecycle_management = 9.3.6`\n- `commerce_guided_search = 11.3.2`\n- `commerce_platform = 11.3.2`\n- `communications_diameter_intelligence_hub >= 8.0.0, <= 8.1.0`\n- `communications_diameter_intelligence_hub >= 8.2.0, <= 8.2.3`\n- `communications_messaging_server = 8.1`\n- `flexcube_private_banking = 12.1.0`\n- `outside_in_technology = 8.5.5`\n- `peoplesoft_enterprise_peopletools = 8.58`\n- `peoplesoft_enterprise_peopletools = 8.59`\n- `retail_bulk_data_integration = 16.0.3`\n- `retail_financial_integration = 14.1.3.2`\n- `retail_financial_integration = 15.0.3.1`\n- `retail_financial_integration = 16.0.3`\n- `retail_financial_integration = 19.0.1`\n- `retail_integration_bus = 14.1.3.2`\n- `retail_integration_bus = 15.0.3.1`\n- `retail_integration_bus = 16.0.3`\n- `retail_integration_bus = 19.0.1`\n- `retail_merchandising_system = 16.0.3`\n- `retail_merchandising_system = 19.0.1`\n- `retail_service_backbone = 14.1.3.2`\n- `retail_service_backbone = 15.0.3.1`\n- `retail_service_backbone = 16.0.3`\n- `retail_service_backbone = 19.0.1`\n- `weblogic_server = 12.2.1.4.0`\n- `weblogic_server = 14.1.1.0.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `santuario_xml_security_for_java 2.2.3`\n- `tomee 8.0.8`\n\n## Vendor advisories\n\n- **RHSA-2021:5149** · Red Hat · fixed in: Red Hat JBoss EAP 7.3 for RHEL 6 Server · released 2021-12-15 · [advisory](https://access.redhat.com/errata/RHSA-2021:5149)\n- **RHSA-2025:4226** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server · released 2025-04-28 · [advisory](https://access.redhat.com/errata/RHSA-2025:4226)\n- **RHSA-2021:5150** · Red Hat · fixed in: Red Hat JBoss EAP 7.3 for RHEL 7 Server · released 2021-12-15 · [advisory](https://access.redhat.com/errata/RHSA-2021:5150)\n- **RHSA-2022:0151** · Red Hat · fixed in: Red Hat Single Sign-On 7.5 for RHEL 7 Server · released 2022-01-17 · [advisory](https://access.redhat.com/errata/RHSA-2022:0151)\n- **RHSA-2021:5151** · Red Hat · fixed in: Red Hat JBoss EAP 7.3 for BaseOS-8 · released 2021-12-15 · [advisory](https://access.redhat.com/errata/RHSA-2021:5151)\n- **RHSA-2022:0164** · Red Hat · fixed in: Middleware Containers for OpenShift · released 2022-01-18 · [advisory](https://access.redhat.com/errata/RHSA-2022:0164)\n- **RHSA-2022:0152** · Red Hat · fixed in: Red Hat Single Sign-On 7.5 for RHEL 8 · released 2022-01-17 · [advisory](https://access.redhat.com/errata/RHSA-2022:0152)\n- **RHSA-2021:5154** · Red Hat · fixed in: EAP 7.3.10 GA · released 2021-12-15 · [advisory](https://access.redhat.com/errata/RHSA-2021:5154)\n- **RHSA-2022:6407** · Red Hat · fixed in: RHAF Camel-K 1.8 · released 2022-09-09 · [advisory](https://access.redhat.com/errata/RHSA-2022:6407)\n- **RHSA-2022:1013** · Red Hat · fixed in: RHINT Camel-Q 2.2.1 · released 2022-03-22 · [advisory](https://access.redhat.com/errata/RHSA-2022:1013)\n- **RHSA-2022:0501** · Red Hat · fixed in: RHINT Service Registry 2.0.3 GA · released 2022-02-09 · [advisory](https://access.redhat.com/errata/RHSA-2022:0501)\n- **Red Hat VEX** · Moderate · affected: Logging Subsystem for Red Hat OpenShift, Red Hat Integration Camel Quarkus 1, Red Hat Integration Service Registry, Red Hat JBoss Data Virtualization 6, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat JBoss Fuse 6, … · no fix planned: Red Hat JBoss Data Virtualization 6, Red Hat JBoss Fuse 6, Red Hat JBoss Fuse Service Works 6, Red Hat JBoss Operations Network 3, … · updated 2026-09-07 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-40690.json)","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":41.3,"likelihood":1.5,"exploitation":0,"ransomware":0},"changes":[]}