CVE-2017-1000246Use of Insufficiently Random Values in Project Pysaml2

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 68.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 17
Latest updateJul 16

Description

Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

debiandebian/python-pysaml2< python-pysaml2 4.5.0-4 (bookworm)

Patches

🔴Vulnerability Details

3
GHSA
Pysaml2 improperly initializes encryption vector2018-07-16
OSV
Pysaml2 improperly initializes encryption vector2018-07-16
OSV
CVE-2017-1000246: Python package pysaml2 version 42017-11-17

📋Vendor Advisories

2
Red Hat
python-pysaml2: Reuse of AES initialization vector in AESCipher2017-05-24
Debian
CVE-2017-1000246: python-pysaml2 - Python package pysaml2 version 4.4.0 and earlier reuses the initialization vecto...2017

💬Community

2
Bugzilla
CVE-2017-1000246 python-pysaml2: Reuse of AES initialization vector in AESCipher2017-12-11
Bugzilla
CVE-2017-1000246 python-pysaml2: various flaws [fedora-all]2017-11-22
CVE-2017-1000246 — Use of Insufficiently Random Values | cvebase