go-saml's XML Digital Signatures use SHA-1
Moderate severity
GitHub Reviewed
Published
Dec 28, 2022
to the GitHub Advisory Database
•
Updated May 20, 2024
Package
Affected versions
<= 0.0.0-20170520135329-fb13cb52a46b
Patched versions
None
Description
Published by the National Vulnerability Database
Dec 28, 2022
Published to the GitHub Advisory Database
Dec 28, 2022
Reviewed
Dec 30, 2022
Last updated
May 20, 2024
XML Digital Signatures generated and validated using this package use SHA-1, which may allow an attacker to craft inputs which cause hash collisions depending on their control over the input.
References