Saml Project

Saml

4 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Published 16.10.2023 19:15:11
  • Last modified 21.11.2024 08:27:12

github.com/crewjam/saml is a saml library for the go language. In affected versions the package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious Service Pro...

  • EPSS 0.19%
  • Published 22.03.2023 20:15:12
  • Last modified 21.11.2024 07:54:26

The crewjam/saml go library contains a partial implementation of the SAML standard in golang. Prior to version 0.4.13, the package's use of `flate.NewReader` does not limit the size of the input. The user can pass more than 1 MB of data in the HTTP r...

  • EPSS 0.26%
  • Published 28.11.2022 15:15:10
  • Last modified 21.11.2024 07:24:03

The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than up...

Exploit
  • EPSS 11.9%
  • Published 21.12.2020 16:15:13
  • Last modified 21.11.2024 05:21:55

A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.