Improper Verification of Cryptographic Signature in gosaml2 - CVE-2020-15216
Published: September 29, 2020 / Updated: April 28, 2026
gosaml2
Russell Haering
Description
The vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists due to improper signature verification in SAML response validation when processing a valid signed SAML response. A remote attacker can modify the document to bypass authentication.
An expired signed SAML response may be sufficient for exploitation.