GHSA-w3wf-cfx3-6gcx

    Dashboard / Vulnerabilities / GHSA-w3wf-cfx3-6gcx

    GHSA-w3wf-cfx3-6gcx

    Published: 11 Feb 2022Last Modified: 10 Sept 2026

    Summary: SAML authentication vulnerability due to stdlib XML parsing

    Details: ### Impact Due to issues in Go's standard library XML parsing, a valid SAML response may be mutated by an attacker to modify the trusted document. This can result in allowing unverified logins from a SAML IdP. Users that configure Fleet with SSO login may be vulnerable to this issue. ### Patches This issue is patched in 3.5.1 using https://github.com/mattermost/xml-roundtrip-validator. ### Workarounds If upgrade to 3.5.1 is not possible, users should disable SSO authentication in Fleet. ### References See https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/ for more information about the underlying vulnerabilities. ### For more information If you have any questions or comments about this advisory: * Email us at [[email protected]](mailto:[email protected]) * Join #fleet in [osquery Slack](https://join.slack.com/t/osquery/shared_invite/zt-h29zm0gk-s2DBtGUTW4CFel0f0IjTEw)

    Affected packages

    Package

    Name: github.com/fleetdm/fleet/v4

    Purl: pkg:golang/github.com/fleetdm/fleet/v4

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -3.5.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-w3wf-cfx3-6gcx | CVE-DB