Xml-crypto package security update advisory

Overview

 

We have released an update to address a vulnerability in the xml-crypto package. users of affected versions are advised to update to the latest version.

 

Affected Products

 

xml-crypto versions: 4.0.0 (inclusive) to 6.0.0 (excluded)

 

Resolved Vulnerabilities

 

xML signature verification bypass due to improper validation of signatures in xml-crypto and signature spoofing (CVE-2024-32962)

 

Vulnerability Patches

 

Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

xml-crypto 6.0.0 version

 

Referenced Sites

 

[1] CVE-2024-32962 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-32962

[2] XML signature verification bypass due improper verification of signature / signature spoofing

https://github.com/node-saml/xml-crypto/security/advisories/GHSA-2xp3-57p7-qf4v