| Name | CVE-2020-29509 |
| Description | The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| Debian Bugs | 948190 |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| golang-1.11 | source | (unstable) | (unfixed) | unimportant | ||
| golang-1.15 | source | (unstable) | (unfixed) | unimportant | ||
| golang-1.7 | source | (unstable) | (unfixed) | unimportant | ||
| golang-1.8 | source | (unstable) | (unfixed) | unimportant | ||
| golang-github-russellhaering-gosaml2 | ITP | 948190 |
Golang upstream does not consider the issue to be fixable in Go, instead
shifts responsibility to saml packages.
https://github.com/golang/go/issues/43168
https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/
https://github.com/russellhaering/gosaml2/security/advisories/GHSA-xhqq-x44f-9fgg