Описание
Security update for lasso
This update for lasso fixes the following issues:
- CVE-2021-28091: Fixed XML signature wrapping vulnerability when parsing SAML responses (boo#1186768)
Список пакетов
openSUSE Leap 15.2
liblasso-devel-2.6.1-lp152.2.3.1
liblasso3-2.6.1-lp152.2.3.1
python3-lasso-2.6.1-lp152.2.3.1
Ссылки
- E-Mail link for openSUSE-SU-2021:1057-1
- SUSE Security Ratings
- SUSE Bug 1186768
- SUSE CVE CVE-2021-28091 page
Описание
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
Затронутые продукты
openSUSE Leap 15.2:liblasso-devel-2.6.1-lp152.2.3.1
openSUSE Leap 15.2:liblasso3-2.6.1-lp152.2.3.1
openSUSE Leap 15.2:python3-lasso-2.6.1-lp152.2.3.1
Ссылки
- CVE-2021-28091
- SUSE Bug 1186768