PT-2021-8018 · Pypi+2 · Pysaml2+2

Juraj Somorovsky

+2

·

Published

2021-01-21

·

Updated

2024-07-12

·

CVE-2021-21238

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions PySAML2 versions prior to 6.5.0
Description The issue is related to an improper verification of cryptographic signatures, specifically a variant of XML Signature wrapping. This occurs because PySAML2 does not validate SAML documents against an XML schema, allowing invalid XML documents to be processed. Such documents can trick PySAML2 with a wrapped signature, potentially enabling a remote attacker to bypass signature verification and access protected information. All users of PySAML2 who need to validate signed SAML documents are impacted.
Recommendations For PySAML2 versions prior to 6.5.0, upgrade to PySAML2 version 6.5.0 to resolve the issue. As a temporary workaround, consider disabling the use of signed SAML documents until the upgrade is possible. Restrict access to sensitive information that relies on SAML authentication to minimize the risk of exploitation.

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1286
ALT-PU-2023-1534
BDU:2024-02841
CVE-2021-21238
GHSA-F4G9-H89H-JGV9
OPENSUSE-SU-2024:11258-1
OPENSUSE-SU-2024:14156-1
PYSEC-2021-48
SUSE-SU-2021:1962-1
SUSE-SU-2021:2554-1

Affected Products

Alt Linux
Pysaml2
Red Os