VDB
Sign up
HIGH

GHSA-c27r-x354-4m68

xml-crypto's HMAC-SHA1 signatures can bypass validation via key confusion

Quick fix

GHSA-c27r-x354-4m68 — xml-crypto: upgrade to the fixed version with the command below.

npm install xml-crypto@2.0.0

Details

### Impact An attacker can inject an HMAC-SHA1 signature that is valid using only knowledge of the RSA public key. This allows bypassing signature validation.

### Patches Version 2.0.0 has the fix.

### Workarounds The recommendation is to upgrade. In case that is not possible remove the 'http://www.w3.org/2000/09/xmldsig#hmac-sha1' entry from SignedXml.SignatureAlgorithms.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/xml-crypto
Introduced in: 0Fixed in: 2.0.0
Fixnpm install xml-crypto@2.0.0

References