Описание
go-saml's XML Digital Signatures use SHA-1
XML Digital Signatures generated and validated using this package use SHA-1, which may allow an attacker to craft inputs which cause hash collisions depending on their control over the input.
Пакеты
Наименование
github.com/RobotsAndPencils/go-saml
go
Затронутые версииВерсия исправления
<= 0.0.0-20170520135329-fb13cb52a46b
Отсутствует
Связанные уязвимости
CVSS3: 5.3
nvd
около 3 лет назад
XML Digital Signatures generated and validated using this package use SHA-1, which may allow an attacker to craft inputs which cause hash collisions depending on their control over the input.