Skip to main content

Vendor archive

saml_project CVEs

Beta · best-effort

4 CVEs tagged to vendor saml_project2 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2023-45683

Published Oct 16, 2023

github.com/crewjam/saml is a saml library for the go language. In affected versions the package does not validate the ACS Location URI according to the SAML binding being parsed.…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28119

Published Mar 22, 2023

The crewjam/saml go library contains a partial implementation of the SAML standard in golang. Prior to version 0.4.13, the package's use of `flate.NewReader` does not limit the si…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-41912

Published Nov 28, 2022

The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1