You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This affects all versions of package github.com/russellhaering/gosaml2. There is a crash on nil-pointer dereference caused by sending malformed XML signatures.
The document mentions #59 which was fixed with #90
You're right, but I'm not quite sure what is causing this. The Snyk report, which the CVE seems to reference, correctly notes that this was resolved in v0.7.0.
I've opened a GitHub Security Advisory reflecting the status of this - perhaps that will propagate to the CVE?
https://ossindex.sonatype.org/vulnerability/CVE-2020-7731?component-type=golang&component-name=github.com%2Frussellhaering%2Fgosaml2
The document mentions #59 which was fixed with #90
Maybe https://ossindex.sonatype.org/vulnerability/CVE-2020-7731?component-type=golang&component-name=github.com%2Frussellhaering%2Fgosaml2 is not up-to-date.
The text was updated successfully, but these errors were encountered: