CVE-2021-23365

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
26/04/2021
Last modified:
19/05/2021

Description

The package github.com/tyktechnologies/tyk-identity-broker before 1.1.1 are vulnerable to Authentication Bypass via the Go XML parser which can cause SAML authentication bypass. This is because the XML parser doesn’t guarantee integrity in the XML round-trip (encoding/decoding XML data).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tyk:tyk-identity-broker:*:*:*:*:*:*:*:* 1.1.1 (excluding)