GHSA-gq5r-cc4w-g8xf – github.com/russellhaering/goxmldsig
Package
Manager: go
Name: github.com/russellhaering/goxmldsig
Vulnerable Version: <0
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0: N/A
EPSS: N/A pctlN/A
Details
Duplicate Advisory: gosaml2 is vulnerable to NULL Pointer Dereference from malformed XML signatures ## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-prjq-f4q3-fvfr. This link is maintained to preserve external references. ## Original Description This affects all versions less than 0.7.0 of package github.com/russellhaering/gosaml2. There is a crash on null pointer dereference caused by sending malformed XML signatures.
Metadata
Created: 2021-06-23T17:25:08Z
Modified: 2024-05-20T20:18:56Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-gq5r-cc4w-g8xf/GHSA-gq5r-cc4w-g8xf.json
CWE IDs: ["CWE-476"]
Alternative ID: N/A
Finding: N/A
Auto approve: 0