The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in multiple products.
The Apache XML Security (Java) is affected by the vulnerability published in US-Cert VU #466161. See: http://www.kb.cert.org/vuls/id/466161 for more information. This bug can allow an attacker to bypass authentication by inserting/modifying a small HMAC truncation length parameter in the XML Signature HMAC based SignatureMethod algorithms.
An inexhaustive list of additional affected products includes:
{
"cwe_ids": [],
"github_reviewed": true,
"github_reviewed_at": "2022-11-08T14:55:27Z",
"nvd_published_at": "2009-07-14T23:30:00Z",
"severity": "MODERATE"
}