EIQ-2021-0003
|
ID |
EIQ-2021-0003 |
|
CVE |
|
|
Description |
PySAML2 improper verification of cryptographic signature |
|
Date |
25 Jan 2021 |
|
Severity |
2 - MEDIUM |
|
CVSSv3 score |
6.5 6.5 |
|
Status |
Planned for 2.10.0 |
|
Assessment |
PySAML2 is a Python implementation of the SAML Version 2 Standard. By default, PySAML2 does not validate the SAML document against an XML schema. |
|
Mitigation |
xmlsec1 needs to be explicitly configured to use only X.509 certificates to verify the SAML document signature. PySAML2 6.5.0 addresses this vulnerability. |
|
Affected versions |
2.9.1 and earlier. |
|
Notes |
For more information, see
See also:
|
< Back to all security issues and mitigation actions
In release notes 2.9.1
In release notes 2.9.2
In release notes 2.10.0