Skip to content

Signature Validation Bypass

Critical
crewjam published GHSA-rrfw-hg9m-j47h Sep 29, 2020

Package

No package listed

Affected versions

v0.4.1

Patched versions

v0.4.2

Description

Impact

An authentication bypass exists in the goxmldsig this library uses to determine if SAML assertions are genuine. An attacker could craft a SAML response that would appear to be valid but would not have been genuinely issued by the IDP.

Patches

Version 0.4.2 bumps the dependency which should fix the issue.

For more information

Please see the advisory in goxmldsig

Credits

The original vulnerability was discovered by @jupenur. Thanks to @russellhaering for the heads up.

Severity

Critical

CVE ID

CVE-2020-15216

Weaknesses

No CWEs

Credits