VYPR
Vendor

RobotsAndPencils

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2023-48703HigMar 6, 2024
    risk 0.49cvss 7.5epss 0.01

    RobotsAndPencils go-saml, a SAML client library written in Go, contains an authentication bypass vulnerability in all known versions. This is due to how the `xmlsec1` command line tool is called internally to verify the signature of SAML assertions. When `xmlsec1` is used…

  • CVE-2020-36563MedDec 28, 2022
    risk 0.27cvss 5.3epss 0.00

    XML Digital Signatures generated and validated using this package use SHA-1, which may allow an attacker to craft inputs which cause hash collisions depending on their control over the input.