GHSA-xfrj-6vvc-3xm2 · Severity: medium · Ecosystem: maven — Apache Santuario - XML Security for Java are vulnerable to private key disclosure
All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclosed in log files when generating an XML Signature and logging with debug level is enabled. Users are recommended to upgrade to version 2.2.6, 2.3.4, or 3.0.3, which fixes this issue.
Conclusion & alert: CVE-2023-44483 is rated Moderate Risk (49.6/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.21%). Core evidence: EPSS rose +1.04% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.17% | 1.21% | +1.04% |
| 2 | 2025-11-21 | 0.57% | 0.17% | -0.40% |
| 3 | 2025-11-18 | — | 0.57% | — |
Full EPSS history (14 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.5 | 3.1 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
GHSA-xfrj-6vvc-3xm2 · Severity: medium · Ecosystem: maven — Apache Santuario - XML Security for Java are vulnerable to private key disclosure
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2023-44483 not yet assigned priority: Debian including 1 source packages (libxml-security-java), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 4, open 1. | https://security-tracker.debian.org/tracker/CVE-2023-44483 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2023-44483 |
ubuntu
|
medium | CVE-2023-44483 medium priority: Ubuntu including 1 source packages (libxml-security-java), 12 status rows across 12 suites (bionic, focal, jammy, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): needs-triage 7, ignored 5. | https://ubuntu.com/security/CVE-2023-44483 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | santuario_xml_security_for_java | < 2.2.6 | cpe:2.3:a:apache:santuario_xml_security_for_java:*:*:*:*:*:*:*:* |
| apache | santuario_xml_security_for_java | >= 2.3.0, < 2.3.4 | cpe:2.3:a:apache:santuario_xml_security_for_java:*:*:*:*:*:*:*:* |
| apache | santuario_xml_security_for_java | >= 3.0.0, < 3.0.3 | cpe:2.3:a:apache:santuario_xml_security_for_java:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2023/10/20/5 | Mailing List Third Party Advisory |
| https://lists.apache.org/thread/vmqbp9mfxtrf0kmbnnmbn3h9j6dr9q55 | Mailing List Vendor Advisory |
| https://security.netapp.com/advisory/ntap-20241108-0002/ |