github.com/crewjam/saml
Activity
- Latest release
- 1y ago
- Total releases
- 19
- Cadence
- ~2 months
- Last 12 months
- 0
Reach
- Stars
- —
Details
- First release
- Oct 31, 2019
| Version | Released | |
|---|---|---|
v0.5.1
patch
|
v0.5.1
patch
Dependencies (7)
|
|
v0.5.0
minor
|
v0.5.0
minor
Dependencies (7)
|
|
v0.4.14
patch
|
v0.4.14
patch
Dependencies (12)
+ 4 more |
|
v0.4.13
patch
1 CVE
CVE-2023-45683
GO-2023-2114
GHSA-267v-3v32-g6q5
Oct 24, 2023
Cross-site scripting via missing binding syntax validation in github.com/crewjam/saml The package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject Javascript in the ACS endpoint definition, achieving Cross-Site-Scripting (XSS) in the IdP context during the redirection at the end of a SAML SSO Flow. Consequently, an attacker may perform any authenticated action as the victim once the victim's browser loads the SAML IdP initiated SSO link for the malicious service provider. Fixed in
0.4.14
References Updated May 20, 2024 · Source: OSV.dev |
v0.4.13
patch
Dependencies (12)
+ 4 more |
|
v0.4.12
patch
2 CVEs
CVE-2023-45683
GO-2023-2114
GHSA-267v-3v32-g6q5
Oct 24, 2023
Cross-site scripting via missing binding syntax validation in github.com/crewjam/saml The package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject Javascript in the ACS endpoint definition, achieving Cross-Site-Scripting (XSS) in the IdP context during the redirection at the end of a SAML SSO Flow. Consequently, an attacker may perform any authenticated action as the victim once the victim's browser loads the SAML IdP initiated SSO link for the malicious service provider. Fixed in
0.4.14
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-28119
GO-2023-1664
GHSA-5mqj-xc49-246p
Aug 23, 2023
Denial of service via deflate compression bomb in github.com/crewjam/saml Denial of service via deflate compression bomb in github.com/crewjam/saml Fixed in
0.4.13
References Updated Aug 07, 2026 · Source: OSV.dev |
v0.4.12
patch
Dependencies (12)
+ 4 more |
|
v0.4.11
patch
2 CVEs
CVE-2023-45683
GO-2023-2114
GHSA-267v-3v32-g6q5
Oct 24, 2023
Cross-site scripting via missing binding syntax validation in github.com/crewjam/saml The package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject Javascript in the ACS endpoint definition, achieving Cross-Site-Scripting (XSS) in the IdP context during the redirection at the end of a SAML SSO Flow. Consequently, an attacker may perform any authenticated action as the victim once the victim's browser loads the SAML IdP initiated SSO link for the malicious service provider. Fixed in
0.4.14
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-28119
GO-2023-1664
GHSA-5mqj-xc49-246p
Aug 23, 2023
Denial of service via deflate compression bomb in github.com/crewjam/saml Denial of service via deflate compression bomb in github.com/crewjam/saml Fixed in
0.4.13
References Updated Aug 07, 2026 · Source: OSV.dev |
v0.4.11
patch
Dependencies (12)
+ 4 more |
|
v0.4.10
patch
2 CVEs
CVE-2023-45683
GO-2023-2114
GHSA-267v-3v32-g6q5
Oct 24, 2023
Cross-site scripting via missing binding syntax validation in github.com/crewjam/saml The package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject Javascript in the ACS endpoint definition, achieving Cross-Site-Scripting (XSS) in the IdP context during the redirection at the end of a SAML SSO Flow. Consequently, an attacker may perform any authenticated action as the victim once the victim's browser loads the SAML IdP initiated SSO link for the malicious service provider. Fixed in
0.4.14
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-28119
GO-2023-1664
GHSA-5mqj-xc49-246p
Aug 23, 2023
Denial of service via deflate compression bomb in github.com/crewjam/saml Denial of service via deflate compression bomb in github.com/crewjam/saml Fixed in
0.4.13
References Updated Aug 07, 2026 · Source: OSV.dev |
v0.4.10
patch
Dependencies (8)
|
|
v0.4.9
patch
2 CVEs
CVE-2023-45683
GO-2023-2114
GHSA-267v-3v32-g6q5
Oct 24, 2023
Cross-site scripting via missing binding syntax validation in github.com/crewjam/saml The package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject Javascript in the ACS endpoint definition, achieving Cross-Site-Scripting (XSS) in the IdP context during the redirection at the end of a SAML SSO Flow. Consequently, an attacker may perform any authenticated action as the victim once the victim's browser loads the SAML IdP initiated SSO link for the malicious service provider. Fixed in
0.4.14
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-28119
GO-2023-1664
GHSA-5mqj-xc49-246p
Aug 23, 2023
Denial of service via deflate compression bomb in github.com/crewjam/saml Denial of service via deflate compression bomb in github.com/crewjam/saml Fixed in
0.4.13
References Updated Aug 07, 2026 · Source: OSV.dev |
v0.4.9
patch
Dependencies (8)
|
|
v0.4.8
patch
3 CVEs
CVE-2023-45683
GO-2023-2114
GHSA-267v-3v32-g6q5
Oct 24, 2023
Cross-site scripting via missing binding syntax validation in github.com/crewjam/saml The package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject Javascript in the ACS endpoint definition, achieving Cross-Site-Scripting (XSS) in the IdP context during the redirection at the end of a SAML SSO Flow. Consequently, an attacker may perform any authenticated action as the victim once the victim's browser loads the SAML IdP initiated SSO link for the malicious service provider. Fixed in
0.4.14
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-28119
GO-2023-1664
GHSA-5mqj-xc49-246p
Aug 23, 2023
Denial of service via deflate compression bomb in github.com/crewjam/saml Denial of service via deflate compression bomb in github.com/crewjam/saml Fixed in
0.4.13
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2022-41912
GHSA-j2jp-wvqg-wc2g
GO-2022-1129
Nov 29, 2022
crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe crewjam/saml go library is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. PatchesThis issue has been corrected in version 0.4.9. CreditThis issue was reported by Felix Wilhelm from Google Project Zero. Fixed in
0.4.9
References
Updated Nov 08, 2023 · Source: OSV.dev |
v0.4.8
patch
Dependencies (8)
|
|
v0.4.7
patch
3 CVEs
CVE-2023-45683
GO-2023-2114
GHSA-267v-3v32-g6q5
Oct 24, 2023
Cross-site scripting via missing binding syntax validation in github.com/crewjam/saml The package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject Javascript in the ACS endpoint definition, achieving Cross-Site-Scripting (XSS) in the IdP context during the redirection at the end of a SAML SSO Flow. Consequently, an attacker may perform any authenticated action as the victim once the victim's browser loads the SAML IdP initiated SSO link for the malicious service provider. Fixed in
0.4.14
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-28119
GO-2023-1664
GHSA-5mqj-xc49-246p
Aug 23, 2023
Denial of service via deflate compression bomb in github.com/crewjam/saml Denial of service via deflate compression bomb in github.com/crewjam/saml Fixed in
0.4.13
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2022-41912
GHSA-j2jp-wvqg-wc2g
GO-2022-1129
Nov 29, 2022
crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe crewjam/saml go library is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. PatchesThis issue has been corrected in version 0.4.9. CreditThis issue was reported by Felix Wilhelm from Google Project Zero. Fixed in
0.4.9
References
Updated Nov 08, 2023 · Source: OSV.dev |
v0.4.7
patch
Dependencies (8)
|
|
v0.4.6
patch
3 CVEs
CVE-2023-45683
GO-2023-2114
GHSA-267v-3v32-g6q5
Oct 24, 2023
Cross-site scripting via missing binding syntax validation in github.com/crewjam/saml The package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject Javascript in the ACS endpoint definition, achieving Cross-Site-Scripting (XSS) in the IdP context during the redirection at the end of a SAML SSO Flow. Consequently, an attacker may perform any authenticated action as the victim once the victim's browser loads the SAML IdP initiated SSO link for the malicious service provider. Fixed in
0.4.14
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-28119
GO-2023-1664
GHSA-5mqj-xc49-246p
Aug 23, 2023
Denial of service via deflate compression bomb in github.com/crewjam/saml Denial of service via deflate compression bomb in github.com/crewjam/saml Fixed in
0.4.13
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2022-41912
GHSA-j2jp-wvqg-wc2g
GO-2022-1129
Nov 29, 2022
crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe crewjam/saml go library is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. PatchesThis issue has been corrected in version 0.4.9. CreditThis issue was reported by Felix Wilhelm from Google Project Zero. Fixed in
0.4.9
References
Updated Nov 08, 2023 · Source: OSV.dev |
v0.4.6
patch
Dependencies (11)
+ 3 more |
|
v0.4.5
patch
3 CVEs
CVE-2023-45683
GO-2023-2114
GHSA-267v-3v32-g6q5
Oct 24, 2023
Cross-site scripting via missing binding syntax validation in github.com/crewjam/saml The package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject Javascript in the ACS endpoint definition, achieving Cross-Site-Scripting (XSS) in the IdP context during the redirection at the end of a SAML SSO Flow. Consequently, an attacker may perform any authenticated action as the victim once the victim's browser loads the SAML IdP initiated SSO link for the malicious service provider. Fixed in
0.4.14
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-28119
GO-2023-1664
GHSA-5mqj-xc49-246p
Aug 23, 2023
Denial of service via deflate compression bomb in github.com/crewjam/saml Denial of service via deflate compression bomb in github.com/crewjam/saml Fixed in
0.4.13
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2022-41912
GHSA-j2jp-wvqg-wc2g
GO-2022-1129
Nov 29, 2022
crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe crewjam/saml go library is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. PatchesThis issue has been corrected in version 0.4.9. CreditThis issue was reported by Felix Wilhelm from Google Project Zero. Fixed in
0.4.9
References
Updated Nov 08, 2023 · Source: OSV.dev |
v0.4.5
patch
Dependencies (10)
+ 2 more |
|
v0.4.4
patch
3 CVEs
CVE-2023-45683
GO-2023-2114
GHSA-267v-3v32-g6q5
Oct 24, 2023
Cross-site scripting via missing binding syntax validation in github.com/crewjam/saml The package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject Javascript in the ACS endpoint definition, achieving Cross-Site-Scripting (XSS) in the IdP context during the redirection at the end of a SAML SSO Flow. Consequently, an attacker may perform any authenticated action as the victim once the victim's browser loads the SAML IdP initiated SSO link for the malicious service provider. Fixed in
0.4.14
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-28119
GO-2023-1664
GHSA-5mqj-xc49-246p
Aug 23, 2023
Denial of service via deflate compression bomb in github.com/crewjam/saml Denial of service via deflate compression bomb in github.com/crewjam/saml Fixed in
0.4.13
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2022-41912
GHSA-j2jp-wvqg-wc2g
GO-2022-1129
Nov 29, 2022
crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe crewjam/saml go library is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. PatchesThis issue has been corrected in version 0.4.9. CreditThis issue was reported by Felix Wilhelm from Google Project Zero. Fixed in
0.4.9
References
Updated Nov 08, 2023 · Source: OSV.dev |
v0.4.4
patch
Dependencies (10)
+ 2 more |
|
v0.4.3
patch
3 CVEs
CVE-2023-45683
GO-2023-2114
GHSA-267v-3v32-g6q5
Oct 24, 2023
Cross-site scripting via missing binding syntax validation in github.com/crewjam/saml The package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject Javascript in the ACS endpoint definition, achieving Cross-Site-Scripting (XSS) in the IdP context during the redirection at the end of a SAML SSO Flow. Consequently, an attacker may perform any authenticated action as the victim once the victim's browser loads the SAML IdP initiated SSO link for the malicious service provider. Fixed in
0.4.14
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-28119
GO-2023-1664
GHSA-5mqj-xc49-246p
Aug 23, 2023
Denial of service via deflate compression bomb in github.com/crewjam/saml Denial of service via deflate compression bomb in github.com/crewjam/saml Fixed in
0.4.13
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2022-41912
GHSA-j2jp-wvqg-wc2g
GO-2022-1129
Nov 29, 2022
crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe crewjam/saml go library is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. PatchesThis issue has been corrected in version 0.4.9. CreditThis issue was reported by Felix Wilhelm from Google Project Zero. Fixed in
0.4.9
References
Updated Nov 08, 2023 · Source: OSV.dev |
v0.4.3
patch
Dependencies (10)
+ 2 more |
|
v0.4.2
patch
4 CVEs
CVE-2023-45683
GO-2023-2114
GHSA-267v-3v32-g6q5
Oct 24, 2023
Cross-site scripting via missing binding syntax validation in github.com/crewjam/saml The package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject Javascript in the ACS endpoint definition, achieving Cross-Site-Scripting (XSS) in the IdP context during the redirection at the end of a SAML SSO Flow. Consequently, an attacker may perform any authenticated action as the victim once the victim's browser loads the SAML IdP initiated SSO link for the malicious service provider. Fixed in
0.4.14
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-28119
GO-2023-1664
GHSA-5mqj-xc49-246p
Aug 23, 2023
Denial of service via deflate compression bomb in github.com/crewjam/saml Denial of service via deflate compression bomb in github.com/crewjam/saml Fixed in
0.4.13
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2022-41912
GHSA-j2jp-wvqg-wc2g
GO-2022-1129
Nov 29, 2022
crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe crewjam/saml go library is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. PatchesThis issue has been corrected in version 0.4.9. CreditThis issue was reported by Felix Wilhelm from Google Project Zero. Fixed in
0.4.9
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-27846
GHSA-4hq8-gmxx-h6w9
BIT-grafana-2020-27846
GO-2021-0058
Jun 23, 2021
XML Processing error in github.com/crewjam/saml
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThere are three vulnerabilities in the go PatchesIn version 0.4.3, all XML input is validated prior to being parsed. Fixed in
0.4.3
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.4.2
patch
Dependencies (9)
+ 1 more |
|
v0.4.1
patch
4 CVEs
CVE-2023-45683
GO-2023-2114
GHSA-267v-3v32-g6q5
Oct 24, 2023
Cross-site scripting via missing binding syntax validation in github.com/crewjam/saml The package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject Javascript in the ACS endpoint definition, achieving Cross-Site-Scripting (XSS) in the IdP context during the redirection at the end of a SAML SSO Flow. Consequently, an attacker may perform any authenticated action as the victim once the victim's browser loads the SAML IdP initiated SSO link for the malicious service provider. Fixed in
0.4.14
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-28119
GO-2023-1664
GHSA-5mqj-xc49-246p
Aug 23, 2023
Denial of service via deflate compression bomb in github.com/crewjam/saml Denial of service via deflate compression bomb in github.com/crewjam/saml Fixed in
0.4.13
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2022-41912
GHSA-j2jp-wvqg-wc2g
GO-2022-1129
Nov 29, 2022
crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe crewjam/saml go library is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. PatchesThis issue has been corrected in version 0.4.9. CreditThis issue was reported by Felix Wilhelm from Google Project Zero. Fixed in
0.4.9
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-27846
GHSA-4hq8-gmxx-h6w9
BIT-grafana-2020-27846
GO-2021-0058
Jun 23, 2021
XML Processing error in github.com/crewjam/saml
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThere are three vulnerabilities in the go PatchesIn version 0.4.3, all XML input is validated prior to being parsed. Fixed in
0.4.3
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.4.1
patch
Dependencies (9)
+ 1 more |
|
v0.4.0
minor
4 CVEs
CVE-2023-45683
GO-2023-2114
GHSA-267v-3v32-g6q5
Oct 24, 2023
Cross-site scripting via missing binding syntax validation in github.com/crewjam/saml The package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject Javascript in the ACS endpoint definition, achieving Cross-Site-Scripting (XSS) in the IdP context during the redirection at the end of a SAML SSO Flow. Consequently, an attacker may perform any authenticated action as the victim once the victim's browser loads the SAML IdP initiated SSO link for the malicious service provider. Fixed in
0.4.14
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-28119
GO-2023-1664
GHSA-5mqj-xc49-246p
Aug 23, 2023
Denial of service via deflate compression bomb in github.com/crewjam/saml Denial of service via deflate compression bomb in github.com/crewjam/saml Fixed in
0.4.13
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2022-41912
GHSA-j2jp-wvqg-wc2g
GO-2022-1129
Nov 29, 2022
crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe crewjam/saml go library is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. PatchesThis issue has been corrected in version 0.4.9. CreditThis issue was reported by Felix Wilhelm from Google Project Zero. Fixed in
0.4.9
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-27846
GHSA-4hq8-gmxx-h6w9
BIT-grafana-2020-27846
GO-2021-0058
Jun 23, 2021
XML Processing error in github.com/crewjam/saml
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThere are three vulnerabilities in the go PatchesIn version 0.4.3, all XML input is validated prior to being parsed. Fixed in
0.4.3
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.4.0
minor
Dependencies (9)
+ 1 more |
|
v0.3.1
patch
4 CVEs
CVE-2023-45683
GO-2023-2114
GHSA-267v-3v32-g6q5
Oct 24, 2023
Cross-site scripting via missing binding syntax validation in github.com/crewjam/saml The package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject Javascript in the ACS endpoint definition, achieving Cross-Site-Scripting (XSS) in the IdP context during the redirection at the end of a SAML SSO Flow. Consequently, an attacker may perform any authenticated action as the victim once the victim's browser loads the SAML IdP initiated SSO link for the malicious service provider. Fixed in
0.4.14
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-28119
GO-2023-1664
GHSA-5mqj-xc49-246p
Aug 23, 2023
Denial of service via deflate compression bomb in github.com/crewjam/saml Denial of service via deflate compression bomb in github.com/crewjam/saml Fixed in
0.4.13
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2022-41912
GHSA-j2jp-wvqg-wc2g
GO-2022-1129
Nov 29, 2022
crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe crewjam/saml go library is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. PatchesThis issue has been corrected in version 0.4.9. CreditThis issue was reported by Felix Wilhelm from Google Project Zero. Fixed in
0.4.9
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-27846
GHSA-4hq8-gmxx-h6w9
BIT-grafana-2020-27846
GO-2021-0058
Jun 23, 2021
XML Processing error in github.com/crewjam/saml
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThere are three vulnerabilities in the go PatchesIn version 0.4.3, all XML input is validated prior to being parsed. Fixed in
0.4.3
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.3.1
patch
Dependencies (8)
|
|
v0.3.0
initial
4 CVEs
CVE-2023-45683
GO-2023-2114
GHSA-267v-3v32-g6q5
Oct 24, 2023
Cross-site scripting via missing binding syntax validation in github.com/crewjam/saml The package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject Javascript in the ACS endpoint definition, achieving Cross-Site-Scripting (XSS) in the IdP context during the redirection at the end of a SAML SSO Flow. Consequently, an attacker may perform any authenticated action as the victim once the victim's browser loads the SAML IdP initiated SSO link for the malicious service provider. Fixed in
0.4.14
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-28119
GO-2023-1664
GHSA-5mqj-xc49-246p
Aug 23, 2023
Denial of service via deflate compression bomb in github.com/crewjam/saml Denial of service via deflate compression bomb in github.com/crewjam/saml Fixed in
0.4.13
References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2022-41912
GHSA-j2jp-wvqg-wc2g
GO-2022-1129
Nov 29, 2022
crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe crewjam/saml go library is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. PatchesThis issue has been corrected in version 0.4.9. CreditThis issue was reported by Felix Wilhelm from Google Project Zero. Fixed in
0.4.9
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-27846
GHSA-4hq8-gmxx-h6w9
BIT-grafana-2020-27846
GO-2021-0058
Jun 23, 2021
XML Processing error in github.com/crewjam/saml
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactThere are three vulnerabilities in the go PatchesIn version 0.4.3, all XML input is validated prior to being parsed. Fixed in
0.4.3
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.3.0
initial
Dependencies (8)
|