This affects all versions of package github.com/russellhaering/goxmldsig. There is a crash on nil-pointer dereference caused by sending malformed XML signatures.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMRUSSELLHAERINGGOXMLDSIG-608301 | broken link |
https://github.com/russellhaering/goxmldsig/issues/48 | third party advisory exploit |