| module: github.com/russellhaering/goxmldsig |
| - module: github.com/russellhaering/gosaml2 |
| - SAMLServiceProvider.validateAssertionSignatures |
| Due to a nil pointer dereference, a malformed XML Digital Signature |
| can cause a panic during validation. If user supplied signatures are |
| being validated, this may be used as a denial of service vector. |
| published: 2021-04-14T12:00:00Z |
| credit: "@stevenjohnstone" |
| - ValidationContext.validateSignature |
| - https://github.com/russellhaering/goxmldsig/issues/48 |
| - https://github.com/russellhaering/gosaml2/issues/59 |