CRITICAL9.1
GHSA-j2jp-wvqg-wc2g
crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
Quick fix
GHSA-j2jp-wvqg-wc2g — github.com/crewjam/saml: upgrade to the fixed version with the command below.
go get github.com/crewjam/saml@v0.4.9Details
### Impact
The crewjam/saml go library is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements.
### Patches
This issue has been corrected in version 0.4.9.
### Credit
This issue was reported by Felix Wilhelm from Google Project Zero.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/crewjam/saml/security/advisories/GHSA-j2jp-wvqg-wc2g[WEB]
- https://github.com/prometheus/exporter-toolkit/security/advisories/GHSA-7rg2-cxvp-9p7p[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2022-41912[ADVISORY]
- https://github.com/crewjam/saml/commit/aee3fb1edeeaf1088fcb458727e0fd863d277f8b[WEB]
- https://github.com/crewjam/saml[PACKAGE]
- https://github.com/crewjam/saml/releases/tag/v0.4.9[WEB]
- https://pkg.go.dev/vuln/GO-2022-1129[WEB]
- http://packetstormsecurity.com/files/170356/crewjam-saml-Signature-Bypass.html[WEB]