漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID
Vulnerability Description
XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID.
_get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolves the SignedInfo Reference/@URI to a node with the XPath expression "//*[@ID='$id']" and returns the first node of the resulting node set. A document in which two elements share that ID value is accepted: the digest and signature are checked against whichever element comes first in document order, and the duplicate is not detected.
Such a document verifies successfully while an application that resolves the same ID independently can read the second, attacker supplied element; in a SAML2 context this places the contents of an Assertion under attacker control.
CVSS Information
N/A
Vulnerability Type
密码学签名的验证不恰当
Vulnerability Title
TIMLEGGE XML::Sig 加密问题漏洞
Vulnerability Description
timlegge XML::Sig是timlegge个人开发者的一款处理XML数字签名的Perl模块。 TIMLEGGE XML::Sig 0.71之前版本存在加密问题漏洞,该漏洞源于使用XPath表达式解析SignedInfo Reference/@URI时仅返回第一个匹配节点,未检测重复ID,导致签名包装攻击,在SAML2上下文中可能使断言内容受攻击者控制。
CVSS Information
N/A
Vulnerability Type
N/A