Lucene search

K
osvGoogleOSV:GO-2021-0058
HistoryApr 14, 2021 - 8:04 p.m.

Signature validation bypass due to XML processing error in github.com/crewjam/saml

2021-04-1420:04:52
Google
osv.dev
10

9.2 High

AI Score

Confidence

High

0.013 Low

EPSS

Percentile

85.6%

Due to the behavior of encoding/xml, a crafted XML document may cause XML Digital Signature validation to be entirely bypassed, causing an unsigned document to appear signed.

CPENameOperatorVersion
github.com/crewjam/samllt0.4.3

9.2 High

AI Score

Confidence

High

0.013 Low

EPSS

Percentile

85.6%