{"id":"GO-2022-0409","details":"An attacker can create an XML file which completely bypasses signature validation,\npassing off an altered file as a signed one.\n","modified":"2022-07-01T20:08:30Z","published":"2022-07-01T20:08:30Z","withdrawn":"2024-05-15T05:37:10.718241Z","references":[{"type":"FIX","url":"https://github.com/russellhaering/goxmldsig/commit/f6188febf0c29d7ffe26a0436212b19cb9615e64"},{"type":"WEB","url":"https://github.com/advisories/GHSA-rrfw-hg9m-j47h"}],"affected":[{"package":{"name":"github.com/russellhaering/goxmldsig","ecosystem":"Go","purl":"pkg:golang/github.com/russellhaering/goxmldsig"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.1.0"}]}],"ecosystem_specific":{"symbols":["ValidationContext.findSignature","ValidationContext.Validate"]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2022-0409.json","url":"https://pkg.go.dev/vuln/GO-2022-0409"}}],"schema_version":"1.7.3"}