VYPR

Signedxml

by Moov

CVEs (1)

  • CVE-2023-34205CriMay 30, 2023
    risk 0.52cvss 9.1epss 0.00

    In Moov signedxml through 1.0.0, parsing the raw XML (as received) can result in different output than parsing the canonicalized XML. Thus, signature validation can be bypassed via a Signature Wrapping attack (aka XSW).