Launch Week Day 1: Announcing Security Design Review
UNKNOWN Go

Signature Validation Bypass

GHSA-rrfw-hg9m-j47h

Published ยท Modified

Description

Impact

An authentication bypass exists in the goxmldsig this library uses to determine if SAML assertions are genuine. An attacker could craft a SAML response that would appear to be valid but would not have been genuinely issued by the IDP.

Patches

Version 0.4.2 bumps the dependency which should fix the issue.

For more information

Please see the advisory in goxmldsig

Credits

The original vulnerability was discovered by @jupenur. Thanks to @russellhaering for the heads up.

Ready to move

Start Securing

Free, no credit card | First findings in minutes