Saml Project Saml vulnerabilities

4 known vulnerabilities affecting saml_project/saml.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2023-45683MEDIUMCVSS 6.1fixed in 0.4.142023-10-16
CVE-2023-45683 [HIGH] CWE-79 CVE-2023-45683: github.com/crewjam/saml is a saml library for the go language. In affected versions the package does github.com/crewjam/saml is a saml library for the go language. In affected versions the package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject Javascript in the ACS endpoint definition, achieving Cross-Site-Scripting (
nvd
CVE-2023-28119HIGHCVSS 7.5v0.4.122023-03-22
CVE-2023-28119 [HIGH] CWE-770 CVE-2023-28119: The crewjam/saml go library contains a partial implementation of the SAML standard in golang. Prior The crewjam/saml go library contains a partial implementation of the SAML standard in golang. Prior to version 0.4.13, the package's use of `flate.NewReader` does not limit the size of the input. The user can pass more than 1 MB of data in the HTTP request to the processing functions, which will be decompressed server-side using the Deflate algorithm.
nvd
CVE-2022-41912CRITICALCVSS 9.8fixed in 0.4.92022-11-28
CVE-2022-41912 [CRITICAL] CWE-287 CVE-2022-41912: The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when pr The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than upgrading to a fixed version.
nvd
CVE-2020-27846CRITICALCVSS 9.8fixed in 0.4.32020-12-21
CVE-2020-27846 [CRITICAL] CWE-115 CVE-2020-27846: A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypas A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
nvd