SB2020121425 - Improper Verification of Cryptographic Signature in gosaml2



SB2020121425 - Improper Verification of Cryptographic Signature in gosaml2

Published: December 14, 2020 Updated: April 28, 2026

Security Bulletin ID SB2020121425
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper Verification of Cryptographic Signature (CVE-ID: CVE-2020-29509)

The vulnerability allows a remote attacker to bypass authentication.

The vulnerability exists due to improper verification of signed XML content in SAML response processing when handling a valid SAML response containing mutated XML content. A remote attacker can modify the XML document so that the library trusts a different portion of the document than was signed to bypass authentication.

Depending on the service provider implementation, the issue may also allow access to an account other than the one authenticated at the identity provider.


Remediation

Install update from vendor's website.