HIGH7.5
GHSA-prjq-f4q3-fvfr
github.com/russellhaering/gosaml2 is vulnerable to NULL Pointer Dereference
Quick fix
GHSA-prjq-f4q3-fvfr — github.com/russellhaering/gosaml2: upgrade to the fixed version with the command below.
go get github.com/russellhaering/gosaml2@v0.7.0Details
### Impact In versions prior to v0.7.0 it was possible for an attacker to supply an invalid assertion which would trigger a panic due to a nil-pointer dereference.
### Patches The issue was patched in v0.7.0, released on March 2, 2022.
### Workarounds Callers to `gosaml2` can use `recover()` to handle panics to mitigate a potential DoS.
### References See issue [#59](https://github.com/russellhaering/gosaml2/issues/59) for details.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/russellhaering/gosaml2
Introduced in:
0Fixed in: 0.7.0Fix
go get github.com/russellhaering/gosaml2@v0.7.0Go/github.com/russellhaering/goxmldsig
Introduced in:
0Fixed in: 1.1.1Fix
go get github.com/russellhaering/goxmldsig@v1.1.1References
- https://github.com/russellhaering/gosaml2/security/advisories/GHSA-prjq-f4q3-fvfr[WEB]
- https://github.com/russellhaering/gosaml2/issues/59[WEB]
- https://github.com/russellhaering/goxmldsig/issues/48[WEB]
- https://github.com/russellhaering/gosaml2/pull/90[WEB]
- https://github.com/russellhaering/gosaml2/commit/66e3b7affd622b8b24ea1e18845f045e46b23424[WEB]
- https://github.com/russellhaering/gosaml2[PACKAGE]
- https://github.com/russellhaering/gosaml2/releases/tag/v0.7.0[WEB]
- https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMRUSSELLHAERINGGOSAML2-608302[WEB]