SB2021020447 - openEuler update for golang



SB2021020447 - openEuler update for golang

Published: February 4, 2021

Security Bulletin ID SB2021020447
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper Verification of Cryptographic Signature (CVE-ID: CVE-2020-29509)

CWE-ID: CWE-347 - Improper Verification of Cryptographic Signature

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authentication.

The vulnerability exists due to improper verification of signed XML content in SAML response processing when handling a valid SAML response containing mutated XML content. A remote attacker can modify the XML document so that the library trusts a different portion of the document than was signed to bypass authentication.

Depending on the service provider implementation, the issue may also allow access to an account other than the one authenticated at the identity provider.


Remediation

Install update from vendor's website.