Количество 9
Количество 9
GHSA-f4g9-h89h-jgv9
SAML XML Signature wrapping in PySAML2
CVE-2021-21238
PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. All users of pysaml2 that need to validate signed SAML documents are impacted. The vulnerability is a variant of XML Signature wrapping because it did not validate the SAML document against an XML schema. This allowed invalid XML documents to be processed and such a document can trick pysaml2 with a wrapped signature. This is fixed in PySAML2 6.5.0.
CVE-2021-21238
PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. All users of pysaml2 that need to validate signed SAML documents are impacted. The vulnerability is a variant of XML Signature wrapping because it did not validate the SAML document against an XML schema. This allowed invalid XML documents to be processed and such a document can trick pysaml2 with a wrapped signature. This is fixed in PySAML2 6.5.0.
CVE-2021-21238
PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. All users of pysaml2 that need to validate signed SAML documents are impacted. The vulnerability is a variant of XML Signature wrapping because it did not validate the SAML document against an XML schema. This allowed invalid XML documents to be processed and such a document can trick pysaml2 with a wrapped signature. This is fixed in PySAML2 6.5.0.
CVE-2021-21238
PySAML2 is a pure python implementation of SAML Version 2 Standard. Py ...
BDU:2024-02841
Уязвимость библиотеки для обмена идентификационными данными по стандарту SAML2 PySAML2, связанная с неправильной проверкой криптографической подписи, позволяющая нарушителю обойти проверку подписи и получить доступ к защищаемой информации
ROS-20240410-12
Уязвимость python3-pysaml2
ALT-PU-2023-1534
ALT-PU-2023-1534: package `python3-module-pysaml2` update to version 7.4.1-alt1
ALT-PU-2023-1286
ALT-PU-2023-1286: package `python3-module-pysaml2` update to version 7.4.0-alt1
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-f4g9-h89h-jgv9 SAML XML Signature wrapping in PySAML2 | CVSS3: 6.5 | 1% Низкий | больше 5 лет назад | |
CVE-2021-21238 PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. All users of pysaml2 that need to validate signed SAML documents are impacted. The vulnerability is a variant of XML Signature wrapping because it did not validate the SAML document against an XML schema. This allowed invalid XML documents to be processed and such a document can trick pysaml2 with a wrapped signature. This is fixed in PySAML2 6.5.0. | CVSS3: 6.5 | 1% Низкий | больше 5 лет назад | |
CVE-2021-21238 PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. All users of pysaml2 that need to validate signed SAML documents are impacted. The vulnerability is a variant of XML Signature wrapping because it did not validate the SAML document against an XML schema. This allowed invalid XML documents to be processed and such a document can trick pysaml2 with a wrapped signature. This is fixed in PySAML2 6.5.0. | CVSS3: 6.5 | 1% Низкий | больше 5 лет назад | |
CVE-2021-21238 PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. All users of pysaml2 that need to validate signed SAML documents are impacted. The vulnerability is a variant of XML Signature wrapping because it did not validate the SAML document against an XML schema. This allowed invalid XML documents to be processed and such a document can trick pysaml2 with a wrapped signature. This is fixed in PySAML2 6.5.0. | CVSS3: 6.5 | 1% Низкий | больше 5 лет назад | |
CVE-2021-21238 PySAML2 is a pure python implementation of SAML Version 2 Standard. Py ... | CVSS3: 6.5 | 1% Низкий | больше 5 лет назад | |
BDU:2024-02841 Уязвимость библиотеки для обмена идентификационными данными по стандарту SAML2 PySAML2, связанная с неправильной проверкой криптографической подписи, позволяющая нарушителю обойти проверку подписи и получить доступ к защищаемой информации | CVSS3: 6.5 | 1% Низкий | больше 5 лет назад | |
ROS-20240410-12 Уязвимость python3-pysaml2 | CVSS3: 6.5 | 1% Низкий | больше 2 лет назад | |
ALT-PU-2023-1534 ALT-PU-2023-1534: package `python3-module-pysaml2` update to version 7.4.1-alt1 | CVSS3: 7.5 | больше 3 лет назад | ||
ALT-PU-2023-1286 ALT-PU-2023-1286: package `python3-module-pysaml2` update to version 7.4.0-alt1 | CVSS3: 7.5 | больше 3 лет назад |
Уязвимостей на страницу