Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Moov signedxml through 1.0.0, parsing the raw XML (as received) can result in different output than parsing the canonicalized XML. Thus, signature validation can be bypassed via a Signature Wrapping attack (aka XSW).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Moov signedxml 数据伪造问题漏洞
Vulnerability Description
signedxml是moov开源的一个用于处理签名 XML 文档的纯 go 库。 Moov signedxml 1.0.0版本及之前版本存在安全漏洞,该漏洞源于解析原始 XML可能会导致与解析规范化 XML 不同的输出,攻击者利用该漏洞可以通过签名包装攻击绕过签名验证。
CVSS Information
N/A
Vulnerability Type
N/A