Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q547-gmf8-8jr7

Опубликовано: 24 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

github.com/russellhaering/goxmldsig vulnerable to Signature Validation Bypass

Impact

With a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one.

Patches

A patch is available, all users of goxmldsig should upgrade to v1.1.0.

For more information

If you have any questions or comments about this advisory open an issue at https://github.com/russellhaering/goxmldsig

Пакеты

Наименование

github.com/russellhaering/goxmldsig

go
Затронутые версииВерсия исправления

< 1.1.0

1.1.0

EPSS

Процентиль: 43%
0.00209
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 5 лет назад

In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is available, all users of goxmldsig should upgrade to at least revision f6188febf0c29d7ffe26a0436212b19cb9615e64 or version 1.1.0

CVSS3: 6.5
redhat
больше 5 лет назад

In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is available, all users of goxmldsig should upgrade to at least revision f6188febf0c29d7ffe26a0436212b19cb9615e64 or version 1.1.0

CVSS3: 5.3
nvd
больше 5 лет назад

In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is available, all users of goxmldsig should upgrade to at least revision f6188febf0c29d7ffe26a0436212b19cb9615e64 or version 1.1.0

CVSS3: 5.3
debian
больше 5 лет назад

In goxmldsig (XML Digital Signatures implemented in pure Go) before ve ...

EPSS

Процентиль: 43%
0.00209
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-347