PT-2021-24382 · Gosaml2 · Gosaml2

Published

2021-05-24

·

Updated

2021-05-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions: gosaml2 versions prior to 0.5.0
Description: Given a valid SAML Response, an attacker can potentially modify the document, bypassing signature validation in order to pass off the altered document as a signed one. This enables a variety of attacks, including users accessing accounts other than the one to which they authenticated in the identity provider, or full authentication bypass if an external attacker can obtain an expired, signed SAML Response.
Recommendations: For gosaml2 versions prior to 0.5.0, upgrade to version 0.5.0 or higher to resolve the issue. As a temporary workaround, consider restricting access to SAML authentication endpoints to minimize the risk of exploitation.

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-5684-G483-2249

Affected Products

Gosaml2