CVE-2023-34205

CRITICAL

Moov signedxml < 1.1.0 - Signature Verification Bypass via Signature Wrapping

Title source: llm
STIX 2.1

Description

In Moov signedxml through 1.0.0, parsing the raw XML (as received) can result in different output than parsing the canonicalized XML. Thus, signature validation can be bypassed via a Signature Wrapping attack (aka XSW).

References (1)

Core 1
Core References
Issue Tracking, Third Party Advisory
https://github.com/moov-io/signedxml/issues/23

Scores

CVSS v3 9.1
EPSS 0.0039
EPSS Percentile 30.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-347
Status published
Products (2)
moov/signedxml 1.0.0
moov-io/signedxml 0 - 1.1.0Go
Published May 30, 2023
Tracked Since Feb 18, 2026