QID 981122

QID 981122: Python (pip) Security Update for pysaml2 (GHSA-cq94-qf6q-mf2h)

Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-cq94-qf6q-mf2h for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981122

    Software Advisories
    Advisory ID Software Component Link
    GHSA-cq94-qf6q-mf2h pysaml2 URL Logo github.com/advisories/GHSA-cq94-qf6q-mf2h