xml-crypto is vulnerable to Incorrect Authorization
80
High Risk
Affected versions are vulnerable to incorrect authorization due to reliance on deprecated APIs: .getReferences() and .references. These methods should not be used, as the data they expose is unsigned and unverified. To mitigate the risk of XML signature wrapping attacks, users are strongly advised to migrate to the .getSignedReferences() API, which ensures proper signature validation.
You are affected if you are using a version that falls within the vulnerable range and you are using the .getReferences() or .references methods.
xml-crypto is vulnerable to Incorrect Authorization in versions 4.0.0 - 6.0.1.
Upgrade the xml-crypto library to the patch version and/or only use the .getSignedReferences() method.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant