Количество 5
Количество 5
CVE-2022-41912
The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than upgrading to a fixed version.
CVE-2022-41912
The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than upgrading to a fixed version.
CVE-2022-41912
The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than upgrading to a fixed version.
CVE-2022-41912
The crewjam/saml go library prior to version 0.4.9 is vulnerable to an ...
GHSA-j2jp-wvqg-wc2g
crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-41912 The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than upgrading to a fixed version. | CVSS3: 9.1 | 2% Низкий | почти 4 года назад | |
CVE-2022-41912 The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than upgrading to a fixed version. | CVSS3: 9.1 | 2% Низкий | почти 4 года назад | |
CVE-2022-41912 The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than upgrading to a fixed version. | CVSS3: 9.1 | 2% Низкий | почти 4 года назад | |
CVE-2022-41912 The crewjam/saml go library prior to version 0.4.9 is vulnerable to an ... | CVSS3: 9.1 | 2% Низкий | почти 4 года назад | |
GHSA-j2jp-wvqg-wc2g crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication | CVSS3: 9.1 | 2% Низкий | почти 4 года назад |
Уязвимостей на страницу