CVE-2020-36563

MEDIUM

XML Digital Signatures - Info Disclosure

Title source: llm
STIX 2.1

Description

XML Digital Signatures generated and validated using this package use SHA-1, which may allow an attacker to craft inputs which cause hash collisions depending on their control over the input.

References (2)

Core 2
Core References
Patch, Vendor Advisory
https://pkg.go.dev/vuln/GO-2020-0047

Scores

CVSS v3 5.3
EPSS 0.0030
EPSS Percentile 21.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-347
Status published
Products (2)
robotsandpencils/go-saml
RobotsAndPencils/go-saml 0Go
Published Dec 28, 2022
Tracked Since Feb 18, 2026