Lucene search

K
osvGoogleOSV:GO-2020-0050
HistoryApr 14, 2021 - 8:04 p.m.

XML digital signature validation bypass in github.com/russellhaering/goxmldsig

2021-04-1420:04:52
Google
osv.dev
12

AI Score

7.5

Confidence

High

EPSS

0.004

Percentile

73.8%

Due to the behavior of encoding/xml, a crafted XML document may cause XML Digital Signature validation to be entirely bypassed, causing an unsigned document to appear signed.

AI Score

7.5

Confidence

High

EPSS

0.004

Percentile

73.8%