blob: 995bc1175bb7e54c0d58479e60550c51c2976556 [file] [log] [blame]
Damien Neilb5cb7652022-08-18 15:09:12 -07001modules:
Damien Neil77344fd2022-05-10 15:03:50 -07002 - module: github.com/russellhaering/gosaml2
Damien Neil77344fd2022-05-10 15:03:50 -07003 versions:
Damien Neildf2d3d32022-05-12 16:02:17 -07004 - fixed: 0.6.0
Tatiana Bradleycf9ad2b2023-01-13 17:38:26 -05005 vulnerable_at: 0.5.0
Damien Neilb5cb7652022-08-18 15:09:12 -07006 packages:
7 - package: github.com/russellhaering/gosaml2
8 symbols:
9 - parseResponse
10 derived_symbols:
11 - SAMLServiceProvider.RetrieveAssertionInfo
12 - SAMLServiceProvider.ValidateEncodedLogoutRequestPOST
13 - SAMLServiceProvider.ValidateEncodedLogoutResponsePOST
14 - SAMLServiceProvider.ValidateEncodedResponse
Roland Shoemakera3a17c92021-04-14 12:59:24 -070015description: |
Jonathan Amsterdam2552b962022-02-02 12:53:36 -050016 Due to the behavior of encoding/xml, a crafted XML document may cause
17 XML Digital Signature validation to be entirely bypassed, causing an
18 unsigned document to appear signed.
Jonathan Amsterdam49ef6142022-02-10 08:53:15 -050019published: 2021-04-14T20:04:52Z
Julie Qiu3008f8a2022-01-04 15:37:42 -050020cves:
21 - CVE-2020-29509
Jonathan Amsterdam1a19dd12022-03-01 10:04:31 -050022ghsas:
23 - GHSA-xhqq-x44f-9fgg
Roland Shoemakera3a17c92021-04-14 12:59:24 -070024credit: Juho Nurminen
Damien Neil00e94d72022-08-26 14:59:35 -070025references:
26 - fix: https://github.com/russellhaering/gosaml2/commit/42606dafba60c58c458f14f75c4c230459672ab9