Vulnerability Description
The package github.com/tyktechnologies/tyk-identity-broker before 1.1.1 are vulnerable to Authentication Bypass via the Go XML parser which can cause SAML authentication bypass. This is because the XML parser doesn’t guarantee integrity in the XML round-trip (encoding/decoding XML data).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tyk | Tyk-Identity-Broker | < 1.1.1 |
Related Weaknesses (CWE)
References
- https://github.com/TykTechnologies/tyk-identity-broker/commit/243092965b0f93a95aPatchThird Party Advisory
- https://github.com/TykTechnologies/tyk-identity-broker/commit/46f70420e0911e4e8bPatchThird Party Advisory
- https://github.com/TykTechnologies/tyk-identity-broker/pull/147PatchThird Party Advisory
- https://github.com/TykTechnologies/tyk-identity-broker/releases/tag/v1.1.1Release NotesThird Party Advisory
- https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMTYKTECHNOLOGIESTYKIDENTITYBROKER-10897Third Party Advisory
- https://github.com/TykTechnologies/tyk-identity-broker/commit/243092965b0f93a95aPatchThird Party Advisory
- https://github.com/TykTechnologies/tyk-identity-broker/commit/46f70420e0911e4e8bPatchThird Party Advisory
- https://github.com/TykTechnologies/tyk-identity-broker/pull/147PatchThird Party Advisory
- https://github.com/TykTechnologies/tyk-identity-broker/releases/tag/v1.1.1Release NotesThird Party Advisory
- https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMTYKTECHNOLOGIESTYKIDENTITYBROKER-10897Third Party Advisory
FAQ
What is CVE-2021-23365?
CVE-2021-23365 is a vulnerability with a CVSS score of 4.8 (MEDIUM). The package github.com/tyktechnologies/tyk-identity-broker before 1.1.1 are vulnerable to Authentication Bypass via the Go XML parser which can cause SAML authentication bypass. This is because the XM...
How severe is CVE-2021-23365?
CVE-2021-23365 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-23365?
Check the references section above for vendor advisories and patch information. Affected products include: Tyk Tyk-Identity-Broker.