blob: 4342ec8ffa9609b68dd07e0df7ee513733fb383d [file] [log] [blame]
Damien Neilb5cb7652022-08-18 15:09:12 -07001modules:
Damien Neil77344fd2022-05-10 15:03:50 -07002 - module: github.com/russellhaering/gosaml2
Damien Neil77344fd2022-05-10 15:03:50 -07003 versions:
Damien Neildf2d3d32022-05-12 16:02:17 -07004 - fixed: 0.6.0
Tatiana Bradleycf9ad2b2023-01-13 17:38:26 -05005 vulnerable_at: 0.5.0
Damien Neilb5cb7652022-08-18 15:09:12 -07006 packages:
7 - package: github.com/russellhaering/gosaml2
8 symbols:
9 - parseResponse
10 derived_symbols:
11 - SAMLServiceProvider.RetrieveAssertionInfo
12 - SAMLServiceProvider.ValidateEncodedLogoutRequestPOST
13 - SAMLServiceProvider.ValidateEncodedLogoutResponsePOST
14 - SAMLServiceProvider.ValidateEncodedResponse
Tatiana Bradley7c92a882023-05-08 13:11:54 -040015summary: 'TODO(https://go.dev/issue/56443): fill in summary field'
Roland Shoemakera3a17c92021-04-14 12:59:24 -070016description: |
Jonathan Amsterdam2552b962022-02-02 12:53:36 -050017 Due to the behavior of encoding/xml, a crafted XML document may cause
18 XML Digital Signature validation to be entirely bypassed, causing an
19 unsigned document to appear signed.
Jonathan Amsterdam49ef6142022-02-10 08:53:15 -050020published: 2021-04-14T20:04:52Z
Julie Qiu3008f8a2022-01-04 15:37:42 -050021cves:
22 - CVE-2020-29509
Jonathan Amsterdam1a19dd12022-03-01 10:04:31 -050023ghsas:
24 - GHSA-xhqq-x44f-9fgg
Roland Shoemakera3a17c92021-04-14 12:59:24 -070025credit: Juho Nurminen
Damien Neil00e94d72022-08-26 14:59:35 -070026references:
27 - fix: https://github.com/russellhaering/gosaml2/commit/42606dafba60c58c458f14f75c4c230459672ab9