Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4hq8-gmxx-h6w9

Опубликовано: 23 июн. 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

XML Processing error in github.com/crewjam/saml

Impact

There are three vulnerabilities in the go encoding/xml package that can allow an attacker to forge part of a signed XML document. For details on this vulnerability see xml-roundtrip-validator

Patches

In version 0.4.3, all XML input is validated prior to being parsed.

Пакеты

Наименование

github.com/crewjam/saml

go
Затронутые версииВерсия исправления

< 0.4.3

0.4.3

EPSS

Процентиль: 94%
0.15345
Средний

9.8 Critical

CVSS3

Дефекты

CWE-115
CWE-287

Связанные уязвимости

CVSS3: 9.8
redhat
больше 4 лет назад

A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 9.8
nvd
больше 4 лет назад

A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

oracle-oval
около 4 лет назад

ELSA-2021-1859: grafana security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 94%
0.15345
Средний

9.8 Critical

CVSS3

Дефекты

CWE-115
CWE-287