Executive brief
An attacker can create an XML file which completely bypasses signature validation, passing off an altered file as a signed one.
Affected products
- Go github.com/russellhaering/goxmldsig
Junglewise Threat Intelligence
Severity: info · Published 2022-07-01
Technologies: github.com/russellhaering/goxmldsig (Go). Vendors: Go.
An attacker can create an XML file which completely bypasses signature validation, passing off an altered file as a signed one.