Critical severity9.8NVD Advisory· Published Dec 21, 2020· Updated Jun 17, 2026
CVE-2020-27846
CVE-2020-27846
Description
A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/crewjam/samlGo | < 0.4.3 | 0.4.3 |
Affected products
11cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_service_mesh:2.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- crewjam/samldescription
- osv-coords2 versions
< 6.7.5+ 1 more
- (no CPE)range: < 6.7.5
- (no CPE)range: < 0.4.3
Patches
Vulnerability mechanics
References
16- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party AdvisoryWEB
- mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-4hq8-gmxx-h6w9ghsaADVISORY
- github.com/crewjam/saml/security/advisories/GHSA-4hq8-gmxx-h6w9nvdThird Party AdvisoryWEB
- grafana.com/blog/2020/12/17/grafana-6.7.5-7.2.3-and-7.3.6-released-with-important-security-fix-for-grafana-enterprise/nvdVendor Advisory
- nvd.nist.gov/vuln/detail/CVE-2020-27846ghsaADVISORY
- security.netapp.com/advisory/ntap-20210205-0002/nvdThird Party Advisory
- github.com/crewjam/saml/commit/da4f1a0612c0a8dd0452cf8b3c7a6518f6b4d053ghsaWEB
- grafana.com/blog/2020/12/17/grafana-6.7.5-7.2.3-and-7.3.6-released-with-important-security-fix-for-grafana-enterpriseghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/3YUTKIRWT6TWU7DS6GF3EOANVQBFQZYIghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/ICP3YRY2VUCNCF2VFUSK77ZMRIC77FEMghsaWEB
- mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilitiesghsaWEB
- pkg.go.dev/vuln/GO-2021-0058ghsaWEB
- security.netapp.com/advisory/ntap-20210205-0002ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3YUTKIRWT6TWU7DS6GF3EOANVQBFQZYI/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ICP3YRY2VUCNCF2VFUSK77ZMRIC77FEM/nvd
News mentions
0No linked articles in our index yet.