CVE-2021-23365
Summary
| CVE | CVE-2021-23365 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-26 10:15:00 UTC |
| Updated | 2021-05-19 13:00:00 UTC |
| Description | The package github.com/tyktechnologies/tyk-identity-broker before 1.1.1 are vulnerable to Authentication Bypass via the Go XML parser which can cause SAML authentication bypass. This is because the XML parser doesn’t guarantee integrity in the XML round-trip (encoding/decoding XML data). |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| TT-1322-Fix SAML vuln and broken tests by jlucktay · Pull Request #147 · TykTechnologies/tyk-identity-broker · GitHub |
CONFIRM |
github.com |
|
| Authentication Bypass in github.com/tyktechnologies/tyk-identity-broker | Snyk |
CONFIRM |
snyk.io |
|
| Merge pull request #147 from TykTechnologies/fix/saml-vuln-and-broken… · TykTechnologies/tyk-identity-broker@46f7042 · GitHub |
CONFIRM |
github.com |
|
| Release v1.1.1 · TykTechnologies/tyk-identity-broker · GitHub |
CONFIRM |
github.com |
|
| Merge branch 'master' into fix/saml-vuln-and-broken-tests · TykTechnologies/tyk-identity-broker@2430929 · GitHub |
CONFIRM |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Sredny M.
Legacy QID Mappings
- 982073 Go (go) Security Update for github.com/tyktechnologies/tyk-identity-broker (GHSA-599h-8wpj-75xj)