SCA: security update for xml-crypto (GHSA-2xp3-57p7-qf4v)

critical Tenable Cloud Security Plugin ID 409176

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- xml-crypto is an xml digital signature and encryption library for Node.js. In affected versions the
default configuration does not check authorization of the signer, it only checks the validity of the
signature per section 3.2.2 of the w3 xmldsig-core-20080610 spec. As such, without additional validation
steps, the default configuration allows a malicious actor to re-sign an XML document, place the
certificate in a `<KeyInfo />` element, and pass `xml-crypto` default validation checks. As a result `xml-
crypto` trusts by default any certificate provided via digitally signed XML document's `<KeyInfo />`.
`xml-crypto` prefers to use any certificate provided via digitally signed XML document's `<KeyInfo />`
even if library was configured to use specific certificate (`publicCert`) for signature verification
purposes. An attacker can spoof signature verification by modifying XML document and replacing existing
signature with signature generated with malicious private key (created by attacker) and by attaching that
private key's certificate to `<KeyInfo />` element. This vulnerability is combination of changes
introduced to `4.0.0` on pull request 301 / commit `c2b83f98` and has been addressed in version 6.0.0 with
pull request 445 / commit `21201723d`. Users are advised to upgrade. Users unable to upgrade may either
check the certificate extracted via `getCertFromKeyInfo` against trusted certificates before accepting the
results of the validation or set `xml-crypto's getCertFromKeyInfo` to `() => undefined` forcing `xml-
crypto` to use an explicitly configured `publicCert` or `privateKey` for signature verification.
(CVE-2024-32962)

See Also

https://github.com/advisories/GHSA-2xp3-57p7-qf4v

Plugin Details

Severity: Critical

ID: 409176

Version: Revision 1.5

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.8

Percentile: 57.51

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2024-32962

CVSS v3

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/1/2024

Vulnerability Publication Date: 5/1/2024

Reference Information

CVE: CVE-2024-32962

cwe: CWE-347