VDB

PYSEC-2017-26

PYSEC-2017-26 PUBLISHED

Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data.

Affected Products

VendorProductVersions
PyPIpysaml22.1.0, 0, 1.0.1

Timeline

  • Nov 17, 2017 CVE Published
  • Nov 8, 2023 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›