VDB
Sign up
HIGH7.5

GHSA-prjq-f4q3-fvfr

github.com/russellhaering/gosaml2 is vulnerable to NULL Pointer Dereference

Quick fix

GHSA-prjq-f4q3-fvfr — github.com/russellhaering/gosaml2: upgrade to the fixed version with the command below.

go get github.com/russellhaering/gosaml2@v0.7.0

Details

### Impact In versions prior to v0.7.0 it was possible for an attacker to supply an invalid assertion which would trigger a panic due to a nil-pointer dereference.

### Patches The issue was patched in v0.7.0, released on March 2, 2022.

### Workarounds Callers to `gosaml2` can use `recover()` to handle panics to mitigate a potential DoS.

### References See issue [#59](https://github.com/russellhaering/gosaml2/issues/59) for details.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/russellhaering/gosaml2
Introduced in: 0Fixed in: 0.7.0
Fixgo get github.com/russellhaering/gosaml2@v0.7.0
Go/github.com/russellhaering/goxmldsig
Introduced in: 0Fixed in: 1.1.1
Fixgo get github.com/russellhaering/goxmldsig@v1.1.1

References