CRITICAL9.8
GHSA-xhqq-x44f-9fgg
Authentication Bypass in github.com/russellhaering/gosaml2
Quick fix
GHSA-xhqq-x44f-9fgg — github.com/russellhaering/gosaml2: upgrade to the fixed version with the command below.
go get github.com/russellhaering/gosaml2@v0.6.0Details
### Impact Given a valid SAML Response, it may be possible for an attacker to mutate the XML document in such a way that gosaml2 will trust a different portion of the document than was signed.
Depending on the implementation of the Service Provider this enables a variety of attacks, including users accessing accounts other than the one to which they authenticated in the Identity Provider, or full authentication bypass.
### Patches Service Providers utilizing gosaml2 should upgrade to v0.6.0 or greater.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/russellhaering/gosaml2
Introduced in:
0Fixed in: 0.6.0Fix
go get github.com/russellhaering/gosaml2@v0.6.0References
- https://github.com/russellhaering/gosaml2/security/advisories/GHSA-xhqq-x44f-9fgg[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2020-29509[ADVISORY]
- https://github.com/russellhaering/gosaml2/commit/42606dafba60c58c458f14f75c4c230459672ab9[WEB]
- https://github.com/mattermost/xml-roundtrip-validator/blob/master/advisories/unstable-attributes.md[WEB]
- https://pkg.go.dev/vuln/GO-2021-0060[WEB]
- https://security.netapp.com/advisory/ntap-20210129-0006[WEB]