Vulnerability Report: GO-2020-0047
- CVE-2020-36563, GHSA-5rhg-xhgr-5hfj
- Affects: github.com/RobotsAndPencils/go-saml
- Published: Apr 14, 2021
- Modified: Jun 12, 2023
XML Digital Signatures generated and validated using this package use SHA-1, which may allow an attacker to craft inputs which cause hash collisions depending on their control over the input.
Affected Packages
-
PathVersionsSymbols
-
all versions, no known fixed
Aliases
References
Feedback
See anything missing or incorrect?
Suggest an edit to this report.