CVE-2020-29510 is a medium-severity vulnerability in the Go encoding/xml package (versions 1.15 and earlier), affecting products like golang go and NetApp Trident. It allows attackers to craft XML inputs that behave inconsistently during different processing stages, potentially leading to authentication bypass, as highlighted by a BleepingComputer article on SAML bypass. With a CVSS score of 5.6, this vulnerability has a network attack vector and low impact on confidentiality, integrity, and availability, but requires high attack complexity. There is no evidence of active exploitation, nor are there public exploits available in Metasploit or ExploitDB, and community discussion is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.15CPE matchmatch criteria | cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:trident:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.