{"api_version":"1","generated_at":"2026-07-23T15:00:15+00:00","cve":"CVE-2021-23365","urls":{"html":"https://cve.report/CVE-2021-23365","api":"https://cve.report/api/cve/CVE-2021-23365.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-23365","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-23365"},"summary":{"title":"CVE-2021-23365","description":"The package github.com/tyktechnologies/tyk-identity-broker before 1.1.1 are vulnerable to Authentication Bypass via the Go XML parser which can cause SAML authentication bypass. This is because the XML parser doesn’t guarantee integrity in the XML round-trip (encoding/decoding XML data).","state":"PUBLIC","assigner":"report@snyk.io","published_at":"2021-04-26 10:15:00","updated_at":"2021-05-19 13:00:00"},"problem_types":["CWE-287"],"metrics":[],"references":[{"url":"https://github.com/TykTechnologies/tyk-identity-broker/pull/147","name":"N/A","refsource":"CONFIRM","tags":[],"title":"TT-1322-Fix SAML vuln and broken tests by jlucktay · Pull Request #147 · TykTechnologies/tyk-identity-broker · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMTYKTECHNOLOGIESTYKIDENTITYBROKER-1089720","name":"N/A","refsource":"CONFIRM","tags":[],"title":"Authentication Bypass in github.com/tyktechnologies/tyk-identity-broker | Snyk","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/TykTechnologies/tyk-identity-broker/commit/46f70420e0911e4e8b638575e29d394c227c75d0","name":"N/A","refsource":"CONFIRM","tags":[],"title":"Merge pull request #147 from TykTechnologies/fix/saml-vuln-and-broken… · TykTechnologies/tyk-identity-broker@46f7042 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/TykTechnologies/tyk-identity-broker/releases/tag/v1.1.1","name":"N/A","refsource":"CONFIRM","tags":[],"title":"Release v1.1.1 · TykTechnologies/tyk-identity-broker · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/TykTechnologies/tyk-identity-broker/commit/243092965b0f93a95a14cb882b5b9a3df61dd5c0","name":"N/A","refsource":"CONFIRM","tags":[],"title":"Merge branch 'master' into fix/saml-vuln-and-broken-tests · TykTechnologies/tyk-identity-broker@2430929 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-23365","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-23365","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Sredny M.","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"23365","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tyk","cpe5":"tyk-identity-broker","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-23365","qid":"982073","title":"Go (go) Security Update for github.com/tyktechnologies/tyk-identity-broker (GHSA-599h-8wpj-75xj)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ASSIGNER":"report@snyk.io","DATE_PUBLIC":"2021-04-26T10:00:35.669586Z","ID":"CVE-2021-23365","STATE":"PUBLIC","TITLE":"Authentication Bypass"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"github.com/TykTechnologies/tyk-identity-broker","version":{"version_data":[{"version_affected":"<","version_value":"1.1.1"}]}}]},"vendor_name":"n/a"}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Authentication Bypass"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMTYKTECHNOLOGIESTYKIDENTITYBROKER-1089720","name":"https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMTYKTECHNOLOGIESTYKIDENTITYBROKER-1089720"},{"refsource":"MISC","url":"https://github.com/TykTechnologies/tyk-identity-broker/releases/tag/v1.1.1","name":"https://github.com/TykTechnologies/tyk-identity-broker/releases/tag/v1.1.1"},{"refsource":"MISC","url":"https://github.com/TykTechnologies/tyk-identity-broker/commit/243092965b0f93a95a14cb882b5b9a3df61dd5c0","name":"https://github.com/TykTechnologies/tyk-identity-broker/commit/243092965b0f93a95a14cb882b5b9a3df61dd5c0"},{"refsource":"MISC","url":"https://github.com/TykTechnologies/tyk-identity-broker/commit/46f70420e0911e4e8b638575e29d394c227c75d0","name":"https://github.com/TykTechnologies/tyk-identity-broker/commit/46f70420e0911e4e8b638575e29d394c227c75d0"},{"refsource":"MISC","url":"https://github.com/TykTechnologies/tyk-identity-broker/pull/147","name":"https://github.com/TykTechnologies/tyk-identity-broker/pull/147"}]},"description":{"description_data":[{"lang":"eng","value":"The package github.com/tyktechnologies/tyk-identity-broker before 1.1.1 are vulnerable to Authentication Bypass via the Go XML parser which can cause SAML authentication bypass. This is because the XML parser doesn’t guarantee integrity in the XML round-trip (encoding/decoding XML data)."}]},"impact":{"cvss":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},"credit":[{"lang":"eng","value":"Sredny M."}]},"nvd":{"publishedDate":"2021-04-26 10:15:00","lastModifiedDate":"2021-05-19 13:00:00","problem_types":["CWE-287"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.2},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:tyk:tyk-identity-broker:*:*:*:*:*:*:*:*","versionEndExcluding":"1.1.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"23365","Ordinal":"198092","Title":"CVE-2021-23365","CVE":"CVE-2021-23365","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"23365","Ordinal":"1","NoteData":"The package github.com/tyktechnologies/tyk-identity-broker before 1.1.1 are vulnerable to Authentication Bypass via the Go XML parser which can cause SAML authentication bypass. This is because the XML parser doesn’t guarantee integrity in the XML round-trip (encoding/decoding XML data).","Type":"Description","Title":null},{"CveYear":"2021","CveId":"23365","Ordinal":"2","NoteData":"2021-04-26","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"23365","Ordinal":"3","NoteData":"2021-04-26","Type":"Other","Title":"Modified"}]}}}