CVE-2021-21238 PUBLISHED

PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. All users of pysaml2 that need to validate signed SAML documents are impacted. The vulnerability is a variant of XML Signature wrapping because it did not validate the SAML document against an XML schema. This allowed invalid XML documents to be processed and such a document can trick pysaml2 with a wrapped signature. This is fixed in PySAML2 6.5.0.

EPSS 0.14% · 33.9th percentile

Risk Scores

EPSS Score
0.14%
33.9th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSpython-pysaml22.4.0-0ubuntu2, 3.0.0-3ubuntu1, 3.0.0-3ubuntu1.16.04.1
Ubuntu:18.04:LTSpython-pysaml24.0.2-0ubuntu3.1, 0, 3.0.0-3ubuntu2
Ubuntu:22.04:LTSpython-pysaml20, 6.1.0-0ubuntu2, 7.1.0-0ubuntu2
Ubuntu:20.04:LTSpython-pysaml24.9.0-0ubuntu2, 0, 4.9.0-0ubuntu3.1

Timeline

References

Open in Interactive Console →