CVE-2022-41912

CRITICAL9.1EPSS 0.30%

crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication

發布日:2022/11/29修改日:2023/11/8
也稱為:GHSA-j2jp-wvqg-wc2gGO-2022-1129

描述

### Impact The crewjam/saml go library is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. ### Patches This issue has been corrected in version 0.4.9. ### Credit This issue was reported by Felix Wilhelm from Google Project Zero.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1CRITICAL9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

參考連結(8)