Описание
Python oic is a Python OpenID Connect implementation. In Python oic before version 1.2.1, there are several related cryptographic issues affecting client implementations that use the library. The issues are: 1) The IdToken signature algorithm was not checked automatically, but only if the expected algorithm was passed in as a kwarg. 2) JWA none algorithm was allowed in all flows. 3) oic.consumer.Consumer.parse_authz returns an unverified IdToken. The verification of the token was left to the discretion of the implementator. 4) iat claim was not checked for sanity (i.e. it could be in the future). These issues are patched in version 1.2.1.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- ProductVendor Advisory
- PatchThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- ProductVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.2.1 (исключая)
cpe:2.3:a:python_openid_connect_project:python_openid_connect:*:*:*:*:*:*:*:*
EPSS
Процентиль: 36%
0.00155
Низкий
6.8 Medium
CVSS3
4.9 Medium
CVSS2
Дефекты
CWE-325
CWE-347
Связанные уязвимости
EPSS
Процентиль: 36%
0.00155
Низкий
6.8 Medium
CVSS3
4.9 Medium
CVSS2
Дефекты
CWE-325
CWE-347