Description
XML Digital Signatures generated and validated using this package use SHA-1, which may allow an attacker to craft inputs which cause hash collisions depending on their control over the input.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7517 | go-saml's XML Digital Signatures use SHA-1 |
Github GHSA |
GHSA-5rhg-xhgr-5hfj | go-saml's XML Digital Signatures use SHA-1 |
References
History
Fri, 11 Apr 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2025-04-11T16:37:19.193Z
Reserved: 2022-07-29T18:37:18.341Z
Link: CVE-2020-36563
Updated: 2024-08-04T17:30:08.406Z
Status : Modified
Published: 2022-12-28T03:15:09.560
Modified: 2025-04-11T17:15:34.783
Link: CVE-2020-36563
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA