Skip to content

XML Processing

High
crewjam published GHSA-4hq8-gmxx-h6w9 Dec 14, 2020

Package

No package listed

Affected versions

< 0.4.2

Patched versions

0.4.3

Description

Impact

There are three vulnerabilities in the go encoding/xml package that can allow an attacker to forge part of a signed XML document. For details on this vulnerability see xml-roundtrip-validator

Patches

In version 0.4.3, all XML input is validated prior to being parsed.

References

Severity

High

CVE ID

CVE-2020-27846

Weaknesses

No CWEs