The W3C XML Signature Syntax and Processing (XMLDsig) specification, starting with 1.0, was originally published with a "RetrievalMethod is a URI ... that may be used to obtain key and/or certificate information" statement and no accompanying information about SSRF risks, and this may have contributed to vulnerable implementations such as those discussed in CVE-2023-36661 and CVE-2024-21893. NOTE: this was mitigated in 1.1 and 2.0 via a directly referenced Best Practices document that calls on implementers to be wary of SSRF.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T02:59:22.218Z
Reserved: 2024-05-06T00:00:00
Link: CVE-2024-34581
Updated: 2024-08-02T02:59:22.218Z
Status : Awaiting Analysis
Published: 2024-06-26T05:15:51.227
Modified: 2024-11-21T09:18:58.680
Link: CVE-2024-34581
No data.
OpenCVE Enrichment
No data.
Weaknesses