Junglewise Threat Intelligence

GO-2022-0409 - An attacker can create an XML file which completely bypasses signature validation, passing off an altered file as a signed one.

Severity: info · Published 2022-07-01

Technologies: github.com/russellhaering/goxmldsig (Go). Vendors: Go.

Executive brief

An attacker can create an XML file which completely bypasses signature validation, passing off an altered file as a signed one.

Affected products

  • Go github.com/russellhaering/goxmldsig

Related threats