Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5684-g483-2249

Опубликовано: 24 мая 2021
Источник: github
Github: Прошло ревью

Описание

Signature Validation Bypass

Impact

Given a valid SAML Response, an attacker can potentially modify the document, bypassing signature validation in order to pass off the altered document as a signed one.

This enables a variety of attacks, including users accessing accounts other than the one to which they authenticated in the identity provider, or full authentication bypass if an external attacker can obtain an expired, signed SAML Response.

Patches

A patch is available, users of gosaml2 should upgrade to v0.5.0 or higher.

References

See the underlying advisory on goxmldsig for more details.

Пакеты

Наименование

github.com/russellhaering/gosaml2

go
Затронутые версииВерсия исправления

< 0.5.0

0.5.0

Дефекты

CWE-347

Дефекты

CWE-347