Xml-crypto package security update advisory
Overview
We have released an update to address a vulnerability in the xml-crypto package. users of affected versions are advised to update to the latest version.
Affected Products
xml-crypto versions: 4.0.0 (inclusive) to 6.0.0 (excluded)
Resolved Vulnerabilities
xML signature verification bypass due to improper validation of signatures in xml-crypto and signature spoofing (CVE-2024-32962)
Vulnerability Patches
Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
xml-crypto 6.0.0 version
Referenced Sites
[1] CVE-2024-32962 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-32962
[2] XML signature verification bypass due improper verification of signature / signature spoofing
https://github.com/node-saml/xml-crypto/security/advisories/GHSA-2xp3-57p7-qf4v