GHSA-rrfw-hg9m-j47h
Signature Validation Bypass
Quick fix
GHSA-rrfw-hg9m-j47h — github.com/russellhaering/goxmldsig: upgrade to the fixed version with the command below.
go get github.com/russellhaering/goxmldsig@v0.4.2Details
### Impact
An authentication bypass exists in the [goxmldsig](https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-q547-gmf8-8jr7) this library uses to determine if SAML assertions are genuine. An attacker could craft a SAML response that would appear to be valid but would not have been genuinely issued by the IDP.
### Patches
Version 0.4.2 bumps the dependency which should fix the issue.
### For more information
Please see [the advisory in goxmldsig](https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-q547-gmf8-8jr7)
## Credits
The original vulnerability was discovered by @jupenur. Thanks to @russellhaering for the heads up.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.4.2go get github.com/russellhaering/goxmldsig@v0.4.2