EIQ-2021-0003
ID |
EIQ-2021-0003 |
CVE |
|
Description |
PySAML2 improper verification of cryptographic signature |
Date |
25 Jan 2021 |
Severity |
2 - MEDIUM |
CVSSv3 score |
6.5 6.5 |
Status |
Planned for 2.10.0 |
Assessment |
PySAML2 is a Python implementation of the SAML Version 2 Standard. By default, PySAML2 does not validate the SAML document against an XML schema. |
Mitigation |
xmlsec1 needs to be explicitly configured to use only X.509 certificates to verify the SAML document signature. PySAML2 6.5.0 addresses this vulnerability. |
Affected versions |
2.9.1 and earlier. |
Notes |
For more information, see
This section is not visible to users accessing the public docs, it's for internal reference See also:
|
< Back to all security issues and mitigation actions
In release notes 2.9.1
In release notes 2.9.2
In release notes 2.10.0