Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-15216

Опубликовано: 29 сент. 2020
Источник: debian
EPSS Низкий

Описание

In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is available, all users of goxmldsig should upgrade to at least revision f6188febf0c29d7ffe26a0436212b19cb9615e64 or version 1.1.0

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-github-russellhaering-goxmldsigfixed1.1.0-1package
golang-github-russellhaering-goxmldsigpostponedbusterpackage

Примечания

  • https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-q547-gmf8-8jr7

  • https://github.com/russellhaering/goxmldsig/commit/f6188febf0c29d7ffe26a0436212b19cb9615e64

EPSS

Процентиль: 43%
0.00209
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 5 лет назад

In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is available, all users of goxmldsig should upgrade to at least revision f6188febf0c29d7ffe26a0436212b19cb9615e64 or version 1.1.0

CVSS3: 6.5
redhat
больше 5 лет назад

In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is available, all users of goxmldsig should upgrade to at least revision f6188febf0c29d7ffe26a0436212b19cb9615e64 or version 1.1.0

CVSS3: 5.3
nvd
больше 5 лет назад

In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is available, all users of goxmldsig should upgrade to at least revision f6188febf0c29d7ffe26a0436212b19cb9615e64 or version 1.1.0

CVSS3: 5.3
github
больше 4 лет назад

github.com/russellhaering/goxmldsig vulnerable to Signature Validation Bypass

EPSS

Процентиль: 43%
0.00209
Низкий