{"id":"GHSA-rrfw-hg9m-j47h","aliases":[],"url":"https://o3.security/vulnerability/GHSA-rrfw-hg9m-j47h","summary":"Signature Validation Bypass","details":"### Impact\n\nAn authentication bypass exists in the [goxmldsig](https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-q547-gmf8-8jr7) this library uses to determine if SAML assertions are genuine. An attacker could craft a SAML response that would appear to be valid but would not have been genuinely issued by the IDP.\n\n### Patches\n\nVersion 0.4.2 bumps the dependency which should fix the issue.\n\n### For more information\n\nPlease see [the advisory in goxmldsig](https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-q547-gmf8-8jr7)\n\n## Credits\n\nThe original vulnerability was discovered by @jupenur. Thanks to @russellhaering for the heads up.","published":"2021-05-24T16:59:42Z","modified":"2021-10-08T21:25:26Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/russellhaering/goxmldsig","fixedVersion":"0.4.2"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/crewjam/saml/security/advisories/GHSA-rrfw-hg9m-j47h"},{"type":"PACKAGE","url":"https://github.com/russellhaering/goxmldsig"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-10-08T21:25:26Z"}}