Intel

AIKIDO-2024-10007

github.com/RobotsAndPencils/go-saml is vulnerable to Authentication bypass

Authentication bypassCVE-2023-48703 Published Mar 1, 2024

100

Critical Risk

This Affects:

Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to authentication bypass, as SAML signatures can be forged when the library is used.

Who does this affect?

You use this package or any fork to authenticate users.

Background info

github.com/RobotsAndPencils/go-saml is vulnerable to Authentication bypass in versions 0.0.0 - 1.0.0.

How to fix this

Stop using this library or check the Github advisory for advanced workarounds.