CVE-2020-13101 Information

Description

In OASIS Digital Signature Services (DSS) 1.0 an attacker can control the validation outcome (i.e. trigger either a valid or invalid outcome for a valid or invalid signature) via a crafted XML signature when the InlineXML option is used. This defeats the expectation of non-repudiation.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Reference

https://www.oasis-open.org/committees/tc_home.php?wg_abbrev=dss-x https://www.oasis-open.org/standardsdssv1.0

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

HIGH

Base Score

NONE

Base Severity

7.5

Share on: