CVE-2020-7711: Denial of Service (DoS)
Published Aug 23, 2020
·Updated
This affects all versions of package github.com/russellhaering/goxmldsig prior to 1.1.1. There is a crash on nil-pointer dereference caused by sending malformed XML signatures. This issue is patched in version 1.1.1.
Other sources
This affects all versions of package github.com/russellhaering/goxmldsig. There is a crash on nil-pointer dereference caused by sending malformed XML signatures.
Affected Software
3 affected componentsFixes available
go/github.com/russellhaering/gosaml2<0.7.0
0.7.0
go/github.com/russellhaering/goxmldsig<1.1.1
1.1.1
Goxmldsig Project Goxmldsig
Event History
Aug 23, 2020
CVE Published
via MITRE·01:35 PM
Data Sourced
via MITRE·01:35 PM
DescriptionSeverityWeakness
Oct 7, 2022
Advisory Published
via GitHub·07:17 AM