Weak hash (SHA-1) in github.com/RobotsAndPencils/go-saml
CVE-2020-36563
5.3MEDIUM
Key Information:
- Vendor
- CVE Published:
- 28 December 2022
What is CVE-2020-36563?
XML Digital Signatures generated and validated using this package use SHA-1, which may allow an attacker to craft inputs which cause hash collisions depending on their control over the input.