{"id":"GHSA-c27r-x354-4m68","summary":"xml-crypto's HMAC-SHA1 signatures can bypass validation via key confusion","details":"### Impact\nAn attacker can inject an HMAC-SHA1 signature that is valid using only knowledge of the RSA public key. This allows bypassing signature validation.\n\n### Patches\nVersion 2.0.0 has the fix.\n\n### Workarounds\nThe recommendation is to upgrade. In case that is not possible remove the 'http://www.w3.org/2000/09/xmldsig#hmac-sha1' entry from SignedXml.SignatureAlgorithms.","modified":"2022-08-02T20:03:05Z","published":"2020-10-27T20:39:46Z","database_specific":{"cwe_ids":["CWE-287"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-10-27T20:35:52Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/yaronn/xml-crypto/security/advisories/GHSA-c27r-x354-4m68"},{"type":"WEB","url":"https://github.com/yaronn/xml-crypto/commit/3d9db712e6232c765cd2ad6bd2902b88a0d22100"},{"type":"PACKAGE","url":"https://github.com/yaronn/xml-crypto"},{"type":"WEB","url":"https://www.npmjs.com/package/xml-crypto"}],"affected":[{"package":{"name":"xml-crypto","ecosystem":"npm","purl":"pkg:npm/xml-crypto"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.0.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 1.5.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/10/GHSA-c27r-x354-4m68/GHSA-c27r-x354-4m68.json"}}],"schema_version":"1.9.0"}