goxmldsig Project goxmldsig

CPE Details

goxmldsig Project goxmldsig
-
2020-08-24
13h30 +00:00
2020-08-24
13h30 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:goxmldsig_project:goxmldsig:-:*:*:*:*:*:*:*

Informations

Vendor

goxmldsig_project

Product

goxmldsig

Version

-

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2020-15216 2020-09-29 14h00 +00:00 In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is available, all users of goxmldsig should upgrade to at least revision f6188febf0c29d7ffe26a0436212b19cb9615e64 or version 1.1.0
6.5
Medium
CVE-2020-7711 2020-08-23 13h35 +00:00 This affects all versions of package github.com/russellhaering/goxmldsig. There is a crash on nil-pointer dereference caused by sending malformed XML signatures.
7.5
High