{"id":"GHSA-c27r-x354-4m68","aliases":[],"url":"https://o3.security/vulnerability/GHSA-c27r-x354-4m68","summary":"xml-crypto's HMAC-SHA1 signatures can bypass validation via key confusion","details":"### Impact\nAn attacker can inject an HMAC-SHA1 signature that is valid using only knowledge of the RSA public key. This allows bypassing signature validation.\n\n### Patches\nVersion 2.0.0 has the fix.\n\n### Workarounds\nThe recommendation is to upgrade. In case that is not possible remove the 'http://www.w3.org/2000/09/xmldsig#hmac-sha1' entry from SignedXml.SignatureAlgorithms.","published":"2020-10-27T20:39:46Z","modified":"2022-08-02T20:03:05Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"xml-crypto","fixedVersion":"2.0.0"}],"fix":{"url":"https://github.com/yaronn/xml-crypto/commit/3d9db712e6232c765cd2ad6bd2902b88a0d22100","label":"yaronn/xml-crypto@3d9db71"},"references":[{"type":"WEB","url":"https://github.com/yaronn/xml-crypto/security/advisories/GHSA-c27r-x354-4m68"},{"type":"WEB","url":"https://github.com/yaronn/xml-crypto/commit/3d9db712e6232c765cd2ad6bd2902b88a0d22100"},{"type":"PACKAGE","url":"https://github.com/yaronn/xml-crypto"},{"type":"WEB","url":"https://www.npmjs.com/package/xml-crypto"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2022-08-02T20:03:05Z"}}