Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The W3C XML Signature Syntax and Processing (XMLDsig) specification, starting with 1.0, was originally published with a "RetrievalMethod is a URI ... that may be used to obtain key and/or certificate information" statement and no accompanying information about SSRF risks, and this may have contributed to vulnerable implementations such as those discussed in CVE-2023-36661 and CVE-2024-21893. NOTE: this was mitigated in 1.1 and 2.0 via a directly referenced Best Practices document that calls on implementers to be wary of SSRF.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
W3C XML Signature 安全漏洞
Vulnerability Description
W3C XML Signature(W3C XMLDsig)是W3C组织的一个定义数字签名的 XML 语法的 W3C 推荐标准。 W3C XML Signature 1.0版本存在安全漏洞。攻击者利用该漏洞可以获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A