blob: 888a56127a2d5cc43e65c3f8f92a7b3dd8a5608e [file] [log] [blame]
packages:
- module: github.com/russellhaering/goxmldsig
symbols:
- ValidationContext.findSignature
versions:
- fixed: 1.1.0
description: |
Due to the behavior of encoding/xml, a crafted XML document may cause
XML Digital Signature validation to be entirely bypassed, causing an
unsigned document to appear signed.
published: 2021-04-14T20:04:52Z
cves:
- CVE-2020-15216
ghsas:
- GHSA-q547-gmf8-8jr7
credit: '@jupenur'
links:
commit: https://github.com/russellhaering/goxmldsig/commit/f6188febf0c29d7ffe26a0436212b19cb9615e64
context:
- https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-q547-gmf8-8jr7