Improper Verification of Cryptographic Signature in gosaml2 - CVE-2020-15216
Published: September 29, 2020 / Updated: April 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists due to improper signature verification in SAML response validation when processing a valid signed SAML response. A remote attacker can modify the document to bypass authentication.
An expired signed SAML response may be sufficient for exploitation.
Affected software
Fedora
golang-github-russellhaering-goxmldsig
How to mitigate CVE-2020-15216
golang-github-russellhaering-goxmldsig - addressed in versions 1.1.0-1.fc32, 1.1.0-1.fc33