VDB
Sign up
HIGH

GHSA-w3wf-cfx3-6gcx

SAML authentication vulnerability due to stdlib XML parsing

Quick fix

GHSA-w3wf-cfx3-6gcx — github.com/fleetdm/fleet/v4: upgrade to the fixed version with the command below.

go get github.com/fleetdm/fleet/v4@v3.5.1

Details

### Impact Due to issues in Go's standard library XML parsing, a valid SAML response may be mutated by an attacker to modify the trusted document. This can result in allowing unverified logins from a SAML IdP.

Users that configure Fleet with SSO login may be vulnerable to this issue.

### Patches This issue is patched in 3.5.1 using https://github.com/mattermost/xml-roundtrip-validator.

### Workarounds If upgrade to 3.5.1 is not possible, users should disable SSO authentication in Fleet.

### References See https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/ for more information about the underlying vulnerabilities.

### For more information If you have any questions or comments about this advisory: * Email us at [security@fleetdm.com](mailto:security@fleetdm.com) * Join #fleet in [osquery Slack](https://join.slack.com/t/osquery/shared_invite/zt-h29zm0gk-s2DBtGUTW4CFel0f0IjTEw)

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/fleetdm/fleet/v4
Introduced in: 0Fixed in: 3.5.1
Fixgo get github.com/fleetdm/fleet/v4@v3.5.1

References