Web Hack List

Other nomination

Exploiting Java's XML Signature Verification

CVE-2022-34169: an integer truncation bug in the XSLTC JIT compiler that Java reaches during XML signature verification. Because XMLDsig lets a signature embed an XSLT transform, an unauthenticated attacker can overflow the generated class constant pool and execute arbitrary JVM bytecode on any SAML endpoint that verifies attacker-supplied signatures.

Record

Researcher
Felix Wilhelm
Published by
projectzero.google

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Felix Wilhelm, first published at the original source. Preserved copies are kept so the citation survives its host.