Bug 2246070 (CVE-2023-44483)

Summary: CVE-2023-44483 santuario: Private Key disclosure in debug-log output
Product: [Other] Security Response Reporter: ybuenos
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aileenc, asoldano, bbaranow, bmaxwell, boliveir, brian.stansberry, cdewolf, chazlett, cmiranda, darran.lofthouse, dkreling, dosoudil, drichtar, eric.wittmann, fjuma, fmariani, fmongiar, gmalinko, ivassile, iweiss, janstey, jcantril, jnethert, jolee, jpoth, jschatte, jstastny, lgao, mosmerov, msochure, mstefank, msvehla, mulliken, nwallace, pantinor, pcongius, pdelbell, pdrozd, peholase, periklis, pjindal, pmackay, pskopek, rowaters, rstancel, smaestri, sthorger, tcunning, tom.jenkinson, yfang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: santuario 2.2.6, santuario 2.3.4, santuario 3.0.3 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2246071, 2260292, 2260293, 2246072    
Bug Blocks: 2245905    

Description ybuenos 2023-10-25 09:06:09 UTC
All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclosed in log files when generating an XML Signature and logging with debug level is enabled. Users are recommended to upgrade to version 2.2.6, 2.3.4, or 3.0.3, which fixes this issue.


https://lists.apache.org/thread/vmqbp9mfxtrf0kmbnnmbn3h9j6dr9q55
http://www.openwall.com/lists/oss-security/2023/10/20/5

Comment 1 ybuenos 2023-10-25 09:06:28 UTC
Created xml-security-c tracking bugs for this issue:

Affects: epel-all [bug 2246071]
Affects: fedora-all [bug 2246072]

Comment 3 Dhananjay Arunesh 2024-01-25 04:28:14 UTC
Created xml-security-c tracking bugs for this issue:

Affects: epel-all [bug 2260292]
Affects: fedora-all [bug 2260293]

Comment 7 errata-xmlrpc 2024-02-06 19:52:01 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9

Via RHSA-2024:0712 https://access.redhat.com/errata/RHSA-2024:0712

Comment 8 errata-xmlrpc 2024-02-06 19:53:03 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7

Via RHSA-2024:0710 https://access.redhat.com/errata/RHSA-2024:0710

Comment 9 errata-xmlrpc 2024-02-06 19:54:53 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8

Via RHSA-2024:0711 https://access.redhat.com/errata/RHSA-2024:0711

Comment 10 errata-xmlrpc 2024-02-06 19:55:41 UTC
This issue has been addressed in the following products:

  EAP 7.4.15

Via RHSA-2024:0714 https://access.redhat.com/errata/RHSA-2024:0714

Comment 11 errata-xmlrpc 2024-02-12 16:02:06 UTC
This issue has been addressed in the following products:

  RHBOAC camel-quarkus 3 (camel-4.0/quarkus-3.2)

Via RHSA-2024:0789 https://access.redhat.com/errata/RHSA-2024:0789

Comment 12 errata-xmlrpc 2024-02-13 16:52:37 UTC
This issue has been addressed in the following products:

  Red Hat Single Sign-On 7.6 for RHEL 8

Via RHSA-2024:0799 https://access.redhat.com/errata/RHSA-2024:0799

Comment 13 errata-xmlrpc 2024-02-13 16:53:06 UTC
This issue has been addressed in the following products:

  Red Hat Single Sign-On 7.6 for RHEL 9

Via RHSA-2024:0800 https://access.redhat.com/errata/RHSA-2024:0800

Comment 14 errata-xmlrpc 2024-02-13 16:53:34 UTC
This issue has been addressed in the following products:

  Red Hat Single Sign-On 7.6 for RHEL 7

Via RHSA-2024:0798 https://access.redhat.com/errata/RHSA-2024:0798

Comment 15 errata-xmlrpc 2024-02-13 16:54:24 UTC
This issue has been addressed in the following products:

  RHEL-8 based Middleware Containers

Via RHSA-2024:0801 https://access.redhat.com/errata/RHSA-2024:0801

Comment 16 errata-xmlrpc 2024-02-13 17:08:09 UTC
This issue has been addressed in the following products:

  Red Hat Single Sign-On

Via RHSA-2024:0804 https://access.redhat.com/errata/RHSA-2024:0804

Comment 17 Paramvir jindal 2024-04-03 04:00:46 UTC
Marking EAP-8 as not affected because EAP 8 GA was released with the fixed version.

Comment 22 errata-xmlrpc 2024-06-06 16:42:10 UTC
This issue has been addressed in the following products:

  Red Hat build of Apache Camel 3.20.6 for Spring Boot

Via RHSA-2024:3708 https://access.redhat.com/errata/RHSA-2024:3708