Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rrfw-hg9m-j47h

Опубликовано: 24 мая 2021
Источник: github
Github: Прошло ревью

Описание

Signature Validation Bypass

Impact

An authentication bypass exists in the goxmldsig this library uses to determine if SAML assertions are genuine. An attacker could craft a SAML response that would appear to be valid but would not have been genuinely issued by the IDP.

Patches

Version 0.4.2 bumps the dependency which should fix the issue.

For more information

Please see the advisory in goxmldsig

Credits

The original vulnerability was discovered by @jupenur. Thanks to @russellhaering for the heads up.

Пакеты

Наименование

github.com/russellhaering/goxmldsig

go
Затронутые версииВерсия исправления

<= 0.4.1

0.4.2

Дефекты

CWE-347

Дефекты

CWE-347