Affected versions of github.com/russellhaering/gosaml2 are vulnerable to Denial of Service (DoS). There is a crash on nil-pointer dereference caused by sending malformed XML signatures. References: https://github.com/russellhaering/gosaml2/issues/59 https://stevenjohnstone.net/posts/snyk/
Mitigated by fix in dependency gosaml2's dependency, github.com/beevik/etree: https://github.com/beevik/etree/commit/4a2f8b9d084c5fffa2fe44a73bd8efaf7dcda53a
External Reference: https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMRUSSELLHAERINGGOSAML2-608302
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-7731