CVE-2020-27846: Misinterpretation of Input
(updated )
A signature verification vulnerability exists in crewjam/saml.
This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
References
Detect and mitigate CVE-2020-27846 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →