Skip to content

Commit cabe5ba

Browse files
authored
Merge pull request #3 from FusionAuth/add-disclosure
Added disclosure for CVE-2021-27736
2 parents 8c89fab + 7530088 commit cabe5ba

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

README.md

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,11 @@ We are very interested in compensating anyone that can identify a security relat
1111

1212
### Disclosures
1313

14+
- CSNC-2021-004 XML External Entity
15+
- Thanks to [Compass Security](https://compass-security.com/) for responsibly disclosing this issue.
16+
- See [CVE-2021-27736](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27736)
17+
- See [CSNC-2021-004](https://www.compass-security.com/fileadmin/Research/Advisories/2021-03_CSNC-2021-004_FusionAuth_SAML_Library_XML_External_Entity.txt)
18+
- Affects versions prior to `0.5.4`, ensure you are using version `0.5.4` or later.
1419
- CNSC-2020-002 Signature Exclusion Attack
1520
- Thanks to [Compass Security](https://compass-security.com/) for responsibly disclosing this issue.
1621
- See [CVE-2020-12676](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12676)

0 commit comments

Comments
 (0)