VDB
Sign up
CRITICAL

GHSA-rrfw-hg9m-j47h

Signature Validation Bypass

Quick fix

GHSA-rrfw-hg9m-j47h — github.com/russellhaering/goxmldsig: upgrade to the fixed version with the command below.

go get github.com/russellhaering/goxmldsig@v0.4.2

Details

### Impact

An authentication bypass exists in the [goxmldsig](https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-q547-gmf8-8jr7) this library uses to determine if SAML assertions are genuine. An attacker could craft a SAML response that would appear to be valid but would not have been genuinely issued by the IDP.

### Patches

Version 0.4.2 bumps the dependency which should fix the issue.

### For more information

Please see [the advisory in goxmldsig](https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-q547-gmf8-8jr7)

## Credits

The original vulnerability was discovered by @jupenur. Thanks to @russellhaering for the heads up.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/russellhaering/goxmldsig
Introduced in: 0Fixed in: 0.4.2
Fixgo get github.com/russellhaering/goxmldsig@v0.4.2

References