Vulnerability Report: GO-2021-0058
- CVE-2020-27846, GHSA-4hq8-gmxx-h6w9
- Affects: github.com/crewjam/saml
- Published: Apr 14, 2021
- Modified: May 20, 2024
Due to the behavior of encoding/xml, a crafted XML document may cause XML Digital Signature validation to be entirely bypassed, causing an unsigned document to appear signed.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.4.3
-
before v0.4.3
-
before v0.4.3
Aliases
References
- https://github.com/crewjam/saml/commit/da4f1a0612c0a8dd0452cf8b3c7a6518f6b4d053
- https://vuln.go.dev/ID/GO-2021-0058.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.