OSV 1.4.0 · github-reviewed · 修改于 2021-10-09 05:25
发布时间
2021-05-25 00:59
GitHub 审查时间
2021-05-22 06:23
NVD 发布时间
—
源文件
advisories/github-reviewed/2021/05/GHSA-rrfw-hg9m-j47h/GHSA-rrfw-hg9m-j47h.json
An authentication bypass exists in the goxmldsig this library uses to determine if SAML assertions are genuine. An attacker could craft a SAML response that would appear to be valid but would not have been genuinely issued by the IDP.
Version 0.4.2 bumps the dependency which should fix the issue.
Please see the advisory in goxmldsig
The original vulnerability was discovered by @jupenur. Thanks to @russellhaering for the heads up.