VDB
Sign up
CRITICAL9.1

GHSA-j2jp-wvqg-wc2g

crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication

Quick fix

GHSA-j2jp-wvqg-wc2g — github.com/crewjam/saml: upgrade to the fixed version with the command below.

go get github.com/crewjam/saml@v0.4.9

Details

### Impact

The crewjam/saml go library is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements.

### Patches

This issue has been corrected in version 0.4.9.

### Credit

This issue was reported by Felix Wilhelm from Google Project Zero.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/crewjam/saml
Introduced in: 0Fixed in: 0.4.9
Fixgo get github.com/crewjam/saml@v0.4.9

References