VDB
Sign up
MEDIUM5.3

GHSA-q547-gmf8-8jr7

github.com/russellhaering/goxmldsig vulnerable to Signature Validation Bypass

Quick fix

GHSA-q547-gmf8-8jr7 — github.com/russellhaering/goxmldsig: upgrade to the fixed version with the command below.

go get github.com/russellhaering/goxmldsig@v1.1.0

Details

### Impact With a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one.

### Patches A patch is available, all users of goxmldsig should upgrade to v1.1.0.

### For more information If you have any questions or comments about this advisory open an issue at https://github.com/russellhaering/goxmldsig

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/russellhaering/goxmldsig
Introduced in: 0Fixed in: 1.1.0
Fixgo get github.com/russellhaering/goxmldsig@v1.1.0

References