CVE-2020-15216
published 2020-09-29CVE-2020-15216: In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass…
PriorityP433medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.90%
55.6th percentile
In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is available, all users of goxmldsig should upgrade to at least revision f6188febf0c29d7ffe26a0436212b19cb9615e64 or version 1.1.0
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | golang-github-russellhaering-goxmldsig | < golang-github-russellhaering-goxmldsig 1.1.0-1 (bookworm) | golang-github-russellhaering-goxmldsig 1.1.0-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| github.com | dexidp_dex | >= 0 < 2.27.0 | 2.27.0 |
| github.com | russellhaering_goxmldsig | >= 0 < 1.1.0 | 1.1.0 |
| goxmldsig_project | goxmldsig | < 1.1.0 | 1.1.0 |
| russellhaering | goxmldsig | < 1.1.0 | 1.1.0 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
ghsa6.5MEDIUM
osv6.5MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Critical security issues in XML encoding in github.com/dexidp/dex
ghsa·2021-12-20·CVSS 6.5
CVE-2020-26290 [MEDIUM] CWE-347 Critical security issues in XML encoding in github.com/dexidp/dex
Critical security issues in XML encoding in github.com/dexidp/dex
### Impact
The following vulnerabilities have been disclosed, which impact users leveraging the SAML connector:
Signature Validation Bypass (CVE-2020-15216): https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-q547-gmf8-8jr7
`encoding/xml` instabilities:
- [Element namespace prefix instability (CVE-2020-29511)](https://github.com/mattermost/xml-roundtrip-validator/blob/master/advisories/unstable-elements.md)
- [Attribute namespace prefix instability (CVE-2020-29509)](https://github.com/mattermost/xml-roundtrip-validator/blob/master/advisories/unstable-attributes.md)
- [Directive comment instability (CVE-2020-29510)](https://github.com/mattermost/xml-roundtrip-validator/blob/master/advisories/unstable-dir
OSV
Critical security issues in XML encoding in github.com/dexidp/dex
osv·2021-12-20·CVSS 6.5
CVE-2020-26290 [MEDIUM] Critical security issues in XML encoding in github.com/dexidp/dex
Critical security issues in XML encoding in github.com/dexidp/dex
### Impact
The following vulnerabilities have been disclosed, which impact users leveraging the SAML connector:
Signature Validation Bypass (CVE-2020-15216): https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-q547-gmf8-8jr7
`encoding/xml` instabilities:
- [Element namespace prefix instability (CVE-2020-29511)](https://github.com/mattermost/xml-roundtrip-validator/blob/master/advisories/unstable-elements.md)
- [Attribute namespace prefix instability (CVE-2020-29509)](https://github.com/mattermost/xml-roundtrip-validator/blob/master/advisories/unstable-attributes.md)
- [Directive comment instability (CVE-2020-29510)](https://github.com/mattermost/xml-roundtrip-validator/blob/master/advisories/unstable-dir
OSV
github.com/russellhaering/goxmldsig vulnerable to Signature Validation Bypass
osv·2021-05-24
CVE-2020-15216 [MEDIUM] github.com/russellhaering/goxmldsig vulnerable to Signature Validation Bypass
github.com/russellhaering/goxmldsig vulnerable to Signature Validation Bypass
### Impact
With a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one.
### Patches
A patch is available, all users of goxmldsig should upgrade to v1.1.0.
### For more information
If you have any questions or comments about this advisory open an issue at https://github.com/russellhaering/goxmldsig
GHSA
github.com/russellhaering/goxmldsig vulnerable to Signature Validation Bypass
ghsa·2021-05-24
CVE-2020-15216 [MEDIUM] CWE-347 github.com/russellhaering/goxmldsig vulnerable to Signature Validation Bypass
github.com/russellhaering/goxmldsig vulnerable to Signature Validation Bypass
### Impact
With a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one.
### Patches
A patch is available, all users of goxmldsig should upgrade to v1.1.0.
### For more information
If you have any questions or comments about this advisory open an issue at https://github.com/russellhaering/goxmldsig
OSV
XML digital signature validation bypass in github.com/russellhaering/goxmldsig
osv·2021-04-14
CVE-2020-15216 XML digital signature validation bypass in github.com/russellhaering/goxmldsig
XML digital signature validation bypass in github.com/russellhaering/goxmldsig
Due to the behavior of encoding/xml, a crafted XML document may cause XML Digital Signature validation to be entirely bypassed, causing an unsigned document to appear signed.
OSV
CVE-2020-15216: In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1
osv·2020-09-29·CVSS 6.5
CVE-2020-15216 [MEDIUM] CVE-2020-15216: In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1
In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is available, all users of goxmldsig should upgrade to at least revision f6188febf0c29d7ffe26a0436212b19cb9615e64 or version 1.1.0
Red Hat
goxmldsig: carefully crafted XML file could allow to bypass signature validation
vendor_redhat·2020-09-30·CVSS 5.3
CVE-2020-15216 [MEDIUM] CWE-347 goxmldsig: carefully crafted XML file could allow to bypass signature validation
goxmldsig: carefully crafted XML file could allow to bypass signature validation
In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is available, all users of goxmldsig should upgrade to at least revision f6188febf0c29d7ffe26a0436212b19cb9615e64 or version 1.1.0
Statement: Whilst the OpenShift Container Platform (OCP) and OpenShift Service Mesh (OSSM) grafana container does include goxmldsig, it is only included as part of the SAML implementation. SAML is only available in the enterprise version of Grafana (https://grafana.com/docs/grafana/latest/auth/saml/). Hence the openshift4/ose-grafana and servicemesh-grafana
Debian
CVE-2020-15216: golang-github-russellhaering-goxmldsig - In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1....
vendor_debian·2020·CVSS 5.3
CVE-2020-15216 [MEDIUM] CVE-2020-15216: golang-github-russellhaering-goxmldsig - In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1....
In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is available, all users of goxmldsig should upgrade to at least revision f6188febf0c29d7ffe26a0436212b19cb9615e64 or version 1.1.0
Scope: local
bookworm: resolved (fixed in 1.1.0-1)
bullseye: resolved (fixed in 1.1.0-1)
sid: resolved (fixed in 1.1.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-15216 goxmldsig: carefully crafted XML file could allow to bypass signature validation
bugzilla·2020-10-01·CVSS 5.3
CVE-2020-15216 [MEDIUM] CVE-2020-15216 goxmldsig: carefully crafted XML file could allow to bypass signature validation
CVE-2020-15216 goxmldsig: carefully crafted XML file could allow to bypass signature validation
In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is available, all users of goxmldsig should upgrade to at least revision f6188febf0c29d7ffe26a0436212b19cb9615e64 or version 1.1.0
Discussion:
Created golang-github-russellhaering-goxmldsig tracking bugs for this issue:
Affects: fedora-all [bug 1884119]
---
Statement:
Whilst the OpenShift Container Platform (OCP) and OpenShift Service Mesh (OSSM) grafana container does include goxmldsig, it is only included as part of the SAML implementation. SAML is only available
Bugzilla
CVE-2020-15216 golang-github-russellhaering-goxmldsig: goxmldsig: carefully crafted XML file could allow to bypass signature validation [fedora-all]
bugzilla·2020-10-01·CVSS 5.3
CVE-2020-15216 [MEDIUM] CVE-2020-15216 golang-github-russellhaering-goxmldsig: goxmldsig: carefully crafted XML file could allow to bypass signature validation [fedora-all]
CVE-2020-15216 golang-github-russellhaering-goxmldsig: goxmldsig: carefully crafted XML file could allow to bypass signature validation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpk
https://github.com/russellhaering/goxmldsig/commit/f6188febf0c29d7ffe26a0436212b19cb9615e64https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-q547-gmf8-8jr7https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GUH33FPUXED3FHYL25BJOQPRKFGPOMS2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZECBFD4M4PHBMBOCMSQ537NOU37QOVWP/https://pkg.go.dev/github.com/russellhaering/goxmldsig?tab=overviewhttps://github.com/russellhaering/goxmldsig/commit/f6188febf0c29d7ffe26a0436212b19cb9615e64https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-q547-gmf8-8jr7https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GUH33FPUXED3FHYL25BJOQPRKFGPOMS2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZECBFD4M4PHBMBOCMSQ537NOU37QOVWP/https://pkg.go.dev/github.com/russellhaering/goxmldsig?tab=overview
2020-09-29
Published