Description


The package github.com/tyktechnologies/tyk-identity-broker before 1.1.1 are vulnerable to Authentication Bypass via the Go XML parser which can cause SAML authentication bypass. This is because the XML parser doesn’t guarantee integrity in the XML round-trip (encoding/decoding XML data).

Related CPE's


Weaknesses



CWE-287

CVSS impact metrics


CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

4.8 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2021-04-26T08:15:12.597Z

4 years ago

Last modified

2024-11-21T04:51:35.020Z

1 year ago