VDB
Sign up
—

GO-2023-1826

Signature validation bypass in github.com/moov-io/signedxml

Quick fix

GO-2023-1826 — github.com/moov-io/signedxml: upgrade to the fixed version with the command below.

go get github.com/moov-io/signedxml@v1.1.0

Details

Signature validation canonicalizes the input XML document before validating the signature. Parsing the uncanonicalized and canonicalized forms can produce different results. An attacker can exploit this variation to bypass signature validation.

Users of signature validation must only parse the canonicalized form of the validated document. The Validator.Validate function does not return the canonical form, and cannot be used safely. Users should only use the Validator.ValidateReferences function and only parse the canonical form which it returns.

The Validator.Validate function was removed in github.com/moov-io/signedxml v1.1.0.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/moov-io/signedxml
Introduced in: 0Fixed in: 1.1.0
Fixgo get github.com/moov-io/signedxml@v1.1.0

References