github.com/crewjam/saml
Go4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/crewjam/samlpage 1 of 1
- CVE-2020-27846CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.4.32020-12-21
A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
- CVE-2022-41912CRITICALCVSS 9.1EG 9.1✓ Fixed in 0.4.92022-11-28
The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds ot…
- CVE-2023-28119HIGHCVSS 7.5EG 7.5✓ Fixed in 0.4.132023-03-22
The crewjam/saml go library contains a partial implementation of the SAML standard in golang. Prior to version 0.4.13, the package's use of `flate.NewReader` does not limit the size of the input. The user can pass more than 1 MB of data in…
- CVE-2023-45683HIGHCVSS 7.1EG 7.1✓ Fixed in 0.4.142023-10-16
github.com/crewjam/saml is a saml library for the go language. In affected versions the package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious …
Check whether github.com/crewjam/saml is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/crewjam/saml CVEs against the assets you own.
Start Free Scan →