Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-15216

Опубликовано: 29 сент. 2020
Источник: nvd
CVSS3: 5.3
CVSS3: 6.5
CVSS2: 4.3
EPSS Низкий

Описание

In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is available, all users of goxmldsig should upgrade to at least revision f6188febf0c29d7ffe26a0436212b19cb9615e64 or version 1.1.0

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:goxmldsig_project:goxmldsig:*:*:*:*:*:*:*:*
Версия до 1.1.0 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*

EPSS

Процентиль: 43%
0.00209
Низкий

5.3 Medium

CVSS3

6.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-347
CWE-347

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 5 лет назад

In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is available, all users of goxmldsig should upgrade to at least revision f6188febf0c29d7ffe26a0436212b19cb9615e64 or version 1.1.0

CVSS3: 6.5
redhat
больше 5 лет назад

In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is available, all users of goxmldsig should upgrade to at least revision f6188febf0c29d7ffe26a0436212b19cb9615e64 or version 1.1.0

CVSS3: 5.3
debian
больше 5 лет назад

In goxmldsig (XML Digital Signatures implemented in pure Go) before ve ...

CVSS3: 5.3
github
больше 4 лет назад

github.com/russellhaering/goxmldsig vulnerable to Signature Validation Bypass

EPSS

Процентиль: 43%
0.00209
Низкий

5.3 Medium

CVSS3

6.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-347
CWE-347