Apache Software Foundation Tomee 8.0.7

CPE Details

Apache Software Foundation Tomee 8.0.7
8.0.7
2022-07-29
14h55 +00:00
2022-07-29
14h58 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:apache:tomee:8.0.7:*:*:*:*:*:*:*

Informations

Vendor

apache

Product

tomee

Version

8.0.7

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-40690 2021-09-18 22h00 +00:00 All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
7.5
High