Lucene search

K
osvGoogleOSV:CVE-2020-15216
HistorySep 29, 2020 - 4:15 p.m.

CVE-2020-15216

2020-09-2916:15:11
Google
osv.dev
5

AI Score

6.7

Confidence

Low

EPSS

0.004

Percentile

73.8%

In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is available, all users of goxmldsig should upgrade to at least revision f6188febf0c29d7ffe26a0436212b19cb9615e64 or version 1.1.0

AI Score

6.7

Confidence

Low

EPSS

0.004

Percentile

73.8%