Description
The W3C XML Signature Syntax and Processing (XMLDsig) specification, starting with 1.0, was originally published with a "RetrievalMethod is a URI ... that may be used to obtain key and/or certificate information" statement and no accompanying information about SSRF risks, and this may have contributed to vulnerable implementations such as those discussed in CVE-2023-36661 and CVE-2024-21893. NOTE: this was mitigated in 1.1 and 2.0 via a directly referenced Best Practices document that calls on implementers to be wary of SSRF.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T02:59:22.218Z
Reserved: 2024-05-06T00:00:00.000Z
Link: CVE-2024-34581
Updated: 2024-08-02T02:59:22.218Z
Status : Deferred
Published: 2024-06-26T05:15:51.227
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-34581
No data.
OpenCVE Enrichment
No data.
Weaknesses