Vulnerability Report: GO-2022-1129
- CVE-2022-41912, GHSA-j2jp-wvqg-wc2g
- Affects: github.com/crewjam/saml
- Published: Nov 29, 2022
- Modified: May 20, 2024
Authentication bypass is possible when processing SAML responses containing multiple Assertion elements.
For detailed information about this vulnerability, visit https://github.com/prometheus/exporter-toolkit/security/advisories/GHSA-7rg2-cxvp-9p7p.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.4.9
Aliases
References
- https://github.com/prometheus/exporter-toolkit/security/advisories/GHSA-7rg2-cxvp-9p7p
- https://github.com/crewjam/saml/commit/aee3fb1edeeaf1088fcb458727e0fd863d277f8b
- https://vuln.go.dev/ID/GO-2022-1129.json
Credits
- Felix Wilhelm from Google Project Zero
Feedback
See anything missing or incorrect?
Suggest an edit to this report.