Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-26244

Опубликовано: 02 дек. 2020
Источник: nvd
CVSS3: 6.8
CVSS2: 4.9
EPSS Низкий

Описание

Python oic is a Python OpenID Connect implementation. In Python oic before version 1.2.1, there are several related cryptographic issues affecting client implementations that use the library. The issues are: 1) The IdToken signature algorithm was not checked automatically, but only if the expected algorithm was passed in as a kwarg. 2) JWA none algorithm was allowed in all flows. 3) oic.consumer.Consumer.parse_authz returns an unverified IdToken. The verification of the token was left to the discretion of the implementator. 4) iat claim was not checked for sanity (i.e. it could be in the future). These issues are patched in version 1.2.1.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:python_openid_connect_project:python_openid_connect:*:*:*:*:*:*:*:*
Версия до 1.2.1 (исключая)

EPSS

Процентиль: 36%
0.00155
Низкий

6.8 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-325
CWE-347

Связанные уязвимости

CVSS3: 6.8
github
около 5 лет назад

Multiple cryptographic issues in Python oic

EPSS

Процентиль: 36%
0.00155
Низкий

6.8 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-325
CWE-347