CVE-2024-34581

June 26, 2024, 12:44 p.m.

None
No Score

Description

The W3C XML Signature Syntax and Processing (XMLDsig) specification, starting with 1.0, was originally published with a "RetrievalMethod is a URI ... that may be used to obtain key and/or certificate information" statement and no accompanying information about SSRF risks, and this may have contributed to vulnerable implementations such as those discussed in CVE-2023-36661 and CVE-2024-21893. NOTE: this was mitigated in 1.1 and 2.0 via a directly referenced Best Practices document that calls on implementers to be wary of SSRF.

Product(s) Impacted

Product Versions
W3C XML Signature Syntax and Processing (XMLDsig) specification
  • ['1.0', '1.1', '2.0']

Weaknesses

Common security weaknesses mapped to this vulnerability.

Timeline

Published: June 26, 2024, 5:15 a.m.
Last Modified: June 26, 2024, 12:44 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

cve@mitre.org

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.