← Vulnerability feed

Vulnerability record · CVE-2023-44483 · published 20 October 2023

CVE-2023-44483: Apache santuario xml security for java sensitive information in log file vulnerability

Apache · Santuario Xml Security For Java

All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclosed in log files when generating an XML Signature and logging with debug level is enabled. Users are recommended to upgrade to version 2.2.6, 2.3.4, or 3.0.3, which fixes this issue.

6.5 CVSS 3.1 Medium EPSS 1.2% · top 32.5% CWE-532 · Sensitive information in log file
6.5CVSS 3.1 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclosed in log files when generating an XML Signature and logging with debug level is enabled. Users are recommended to upgrade to version 2.2.6, 2.3.4, or 3.0.3, which fixes this issue.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-44483 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2021-40690Apache santuario xml security for java information exposure vulnerabilityAll versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is…EPSS 7.4%5.5CVE-2019-12400Apache santuario xml security for java improper input validation vulnerabilityIn version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static poo…EPSS 0.78%5.0CVE-2014-8152Apache santuario xml security for java vulnerabilityApache Santuario XML Security for Java 2.0.x before 2.0.3 allows remote attackers to bypass the streaming XML signature protection mechanism via a cr…EPSS 5.6%4.3CVE-2013-4517Apache santuario xml security for java vulnerabilityApache Santuario XML Security for Java before 1.5.6, when applying Transforms, allows remote attackers to cause a denial of service (memory consumpti…EPSS 8.9%4.3CVE-2013-2172Apache santuario xml security for java vulnerabilityjcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows c…EPSS 5.9%4.6CVE-2025-24984Windows NTFS logs sensitive information, enabling physical-attack disclosureWindows NTFS writes sensitive information into a log file, which an attacker can read to disclose data. The flaw is rated CVSS 3.1 4.6 (Medium) and a…KEVEPSS 2.0%analysed4.4CVE-2023-21492Samsung Android kernel pointer logging enables ASLR bypassSamsung Android devices log kernel pointers to a log file before the SMR May-2023 Release 1 fix. A privileged local attacker who can read those logs …KEVEPSS 2.6%analysed

Source: NIST National Vulnerability Database (record CVE-2023-44483), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.