{"id":"GHSA-rrfw-hg9m-j47h","summary":"Signature Validation Bypass","details":"### Impact\n\nAn authentication bypass exists in the [goxmldsig](https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-q547-gmf8-8jr7) this library uses to determine if SAML assertions are genuine. An attacker could craft a SAML response that would appear to be valid but would not have been genuinely issued by the IDP.\n\n### Patches\n\nVersion 0.4.2 bumps the dependency which should fix the issue.\n\n### For more information\n\nPlease see [the advisory in goxmldsig](https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-q547-gmf8-8jr7)\n\n## Credits\n\nThe original vulnerability was discovered by @jupenur. Thanks to @russellhaering for the heads up.","modified":"2021-10-08T21:25:26Z","published":"2021-05-24T16:59:42Z","database_specific":{"github_reviewed_at":"2021-05-21T22:23:03Z","nvd_published_at":null,"cwe_ids":["CWE-347"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/crewjam/saml/security/advisories/GHSA-rrfw-hg9m-j47h"},{"type":"PACKAGE","url":"https://github.com/russellhaering/goxmldsig"}],"affected":[{"package":{"name":"github.com/russellhaering/goxmldsig","ecosystem":"Go","purl":"pkg:golang/github.com/russellhaering/goxmldsig"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.4.2"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.4.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-rrfw-hg9m-j47h/GHSA-rrfw-hg9m-j47h.json"}}],"schema_version":"1.9.0"}