Логотип exploitDog
bind:CVE-2020-5390
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-5390

Количество 6

Количество 6

ubuntu логотип

CVE-2020-5390

около 6 лет назад

PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object that is signed can be in different places and thus the signature verification will succeed, but the wrong data will be used. This specifically affects the verification of assertion that have been signed.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2020-5390

около 6 лет назад

PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object that is signed can be in different places and thus the signature verification will succeed, but the wrong data will be used. This specifically affects the verification of assertion that have been signed.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2020-5390

около 6 лет назад

PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object that is signed can be in different places and thus the signature verification will succeed, but the wrong data will be used. This specifically affects the verification of assertion that have been signed.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2020-5390

около 6 лет назад

PySAML2 before 5.0.0 does not check that the signature in a SAML docum ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-qf7v-8hj3-4xw7

почти 6 лет назад

Improper Verification of Cryptographic Signature in PySAML2

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2020-05775

около 6 лет назад

Уязвимость библиотеки для обмена идентификационными данными по стандарту SAML2 PySAML2, связанная с некорректным подтверждением криптографической подписи данных, позволяющая нарушителю обойти проверку подписи и получить доступ к защищаемой информации

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-5390

PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object that is signed can be in different places and thus the signature verification will succeed, but the wrong data will be used. This specifically affects the verification of assertion that have been signed.

CVSS3: 7.5
1%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-5390

PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object that is signed can be in different places and thus the signature verification will succeed, but the wrong data will be used. This specifically affects the verification of assertion that have been signed.

CVSS3: 7.5
1%
Низкий
около 6 лет назад
nvd логотип
CVE-2020-5390

PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object that is signed can be in different places and thus the signature verification will succeed, but the wrong data will be used. This specifically affects the verification of assertion that have been signed.

CVSS3: 7.5
1%
Низкий
около 6 лет назад
debian логотип
CVE-2020-5390

PySAML2 before 5.0.0 does not check that the signature in a SAML docum ...

CVSS3: 7.5
1%
Низкий
около 6 лет назад
github логотип
GHSA-qf7v-8hj3-4xw7

Improper Verification of Cryptographic Signature in PySAML2

CVSS3: 7.5
1%
Низкий
почти 6 лет назад
fstec логотип
BDU:2020-05775

Уязвимость библиотеки для обмена идентификационными данными по стандарту SAML2 PySAML2, связанная с некорректным подтверждением криптографической подписи данных, позволяющая нарушителю обойти проверку подписи и получить доступ к защищаемой информации

CVSS3: 7.5
1%
Низкий
около 6 лет назад

Уязвимостей на страницу