Lucene search

K
osvGoogleOSV:GO-2020-0047
HistoryApr 14, 2021 - 8:04 p.m.

Weak hash (SHA-1) in github.com/RobotsAndPencils/go-saml

2021-04-1420:04:52
Google
osv.dev
10

0.001 Low

EPSS

Percentile

32.6%

XML Digital Signatures generated and validated using this package use SHA-1, which may allow an attacker to craft inputs which cause hash collisions depending on their control over the input.

0.001 Low

EPSS

Percentile

32.6%