Vulnerability Description
In OASIS Digital Signature Services (DSS) 1.0, an attacker can control the validation outcome (i.e., trigger either a valid or invalid outcome for a valid or invalid signature) via a crafted XML signature, when the InlineXML option is used. This defeats the expectation of non-repudiation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oasis-Open | Oasis Digital Signature Services | 1.0 |
Related Weaknesses (CWE)
References
- https://www.oasis-open.org/apps/org/workgroup/dss-x/Permissions RequiredVendor Advisory
- https://www.oasis-open.org/committees/tc_home.php?wg_abbrev=dss-xVendor Advisory
- https://www.oasis-open.org/standards#dssv1.0Vendor Advisory
- https://www.oasis-open.org/apps/org/workgroup/dss-x/Permissions RequiredVendor Advisory
- https://www.oasis-open.org/committees/tc_home.php?wg_abbrev=dss-xVendor Advisory
- https://www.oasis-open.org/standards#dssv1.0Vendor Advisory
FAQ
What is CVE-2020-13101?
CVE-2020-13101 is a vulnerability with a CVSS score of 7.5 (HIGH). In OASIS Digital Signature Services (DSS) 1.0, an attacker can control the validation outcome (i.e., trigger either a valid or invalid outcome for a valid or invalid signature) via a crafted XML signa...
How severe is CVE-2020-13101?
CVE-2020-13101 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-13101?
Check the references section above for vendor advisories and patch information. Affected products include: Oasis-Open Oasis Digital Signature Services.