Saml Project Saml 0.1.0 for Go

CPE Details

Saml Project Saml 0.1.0 for Go
0.1.0
2020-12-23
12h57 +00:00
2021-04-20
18h23 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:saml_project:saml:0.1.0:*:*:*:*:go:*:*

Informations

Vendor

saml_project

Product

saml

Version

0.1.0

Target Software

go

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2023-45683 2023-10-16 18h13 +00:00 github.com/crewjam/saml is a saml library for the go language. In affected versions the package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject Javascript in the ACS endpoint definition, achieving Cross-Site-Scripting (XSS) in the IdP context during the redirection at the end of a SAML SSO Flow. Consequently, an attacker may perform any authenticated action as the victim once the victim’s browser loaded the SAML IdP initiated SSO link for the malicious service provider. Note: SP registration is commonly an unrestricted operation in IdPs, hence not requiring particular permissions or publicly accessible to ease the IdP interoperability. This issue is fixed in version 0.4.14. Users unable to upgrade may perform external validation of URLs provided in SAML metadata, or restrict the ability for end-users to upload arbitrary metadata.
7.1
Haute
CVE-2022-41912 2022-11-27 23h00 +00:00 The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than upgrading to a fixed version.
9.8
Critique
CVE-2020-27846 2020-12-21 14h16 +00:00 A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
9.8
Critique