CVE-2020-5390
published 2020-01-13CVE-2020-5390: PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML…
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
1.22%
65.8th percentile
PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object that is signed can be in different places and thus the signature verification will succeed, but the wrong data will be used. This specifically affects the verification of assertion that have been signed.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | python-pysaml2 | < python-pysaml2 4.5.0-7 (bookworm) | python-pysaml2 4.5.0-7 (bookworm) |
| pysaml2_project | pysaml2 | < 5.0.0 | 5.0.0 |
| pysaml2_project | pysaml2 | >= 0 < 5.0.0 | 5.0.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Verification of Cryptographic Signature in PySAML2
osv·2020-05-06
CVE-2020-5390 [HIGH] Improper Verification of Cryptographic Signature in PySAML2
Improper Verification of Cryptographic Signature in PySAML2
PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object that is signed can be in different places and thus the signature verification will succeed, but the wrong data will be used. This specifically affects the verification of assertions that have been signed.
GHSA
Improper Verification of Cryptographic Signature in PySAML2
ghsa·2020-05-06
CVE-2020-5390 [HIGH] CWE-347 Improper Verification of Cryptographic Signature in PySAML2
Improper Verification of Cryptographic Signature in PySAML2
PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object that is signed can be in different places and thus the signature verification will succeed, but the wrong data will be used. This specifically affects the verification of assertions that have been signed.
OSV
CVE-2020-5390: PySAML2 before 5
osv·2020-01-13·CVSS 7.5
CVE-2020-5390 [HIGH] CVE-2020-5390: PySAML2 before 5
PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object that is signed can be in different places and thus the signature verification will succeed, but the wrong data will be used. This specifically affects the verification of assertion that have been signed.
Ubuntu
PySAML2 vulnerability
vendor_ubuntu·2020-01-21
CVE-2020-5390 PySAML2 vulnerability
Title: PySAML2 vulnerability
Summary: PySAML2 could be made to bypass signature verification with arbitrary data.
It was discovered that PySAML2 incorrectly handled certain SAML files.
An attacker could possibly use this issue to bypass signature verification
with arbitrary data.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python-pysaml2: does not check that the signature in a SAML document is enveloped
vendor_redhat·2020-01-13·CVSS 7.5
CVE-2020-5390 [HIGH] CWE-347 python-pysaml2: does not check that the signature in a SAML document is enveloped
python-pysaml2: does not check that the signature in a SAML document is enveloped
PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object that is signed can be in different places and thus the signature verification will succeed, but the wrong data will be used. This specifically affects the verification of assertion that have been signed.
A verification flaw was found in python-pysaml2, where it did not check that the signature in a SAML document was enveloped, which enabled XML signature wrapping (XSW) attacks. A remote attacker could exploit this flaw to convince SAML processing to verify the signature and accept m
Debian
CVE-2020-5390: python-pysaml2 - PySAML2 before 5.0.0 does not check that the signature in a SAML document is env...
vendor_debian·2020·CVSS 7.5
CVE-2020-5390 [HIGH] CVE-2020-5390: python-pysaml2 - PySAML2 before 5.0.0 does not check that the signature in a SAML document is env...
PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object that is signed can be in different places and thus the signature verification will succeed, but the wrong data will be used. This specifically affects the verification of assertion that have been signed.
Scope: local
bookworm: resolved (fixed in 4.5.0-7)
bullseye: resolved (fixed in 4.5.0-7)
forky: resolved (fixed in 4.5.0-7)
sid: resolved (fixed in 4.5.0-7)
trixie: resolved (fixed in 4.5.0-7)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-5390 python-pysaml2: does not check that the signature in a SAML document is enveloped [openstack-rdo]
bugzilla·2020-01-24·CVSS 7.5
CVE-2020-5390 [HIGH] CVE-2020-5390 python-pysaml2: does not check that the signature in a SAML document is enveloped [openstack-rdo]
CVE-2020-5390 python-pysaml2: does not check that the signature in a SAML document is enveloped [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Th
Bugzilla
CVE-2020-5390 python-pysaml2: does not check that the signature in a SAML document is enveloped
bugzilla·2020-01-24·CVSS 7.5
CVE-2020-5390 [HIGH] CVE-2020-5390 python-pysaml2: does not check that the signature in a SAML document is enveloped
CVE-2020-5390 python-pysaml2: does not check that the signature in a SAML document is enveloped
PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object that is signed can be in different places and thus the signature verification will succeed, but the wrong data will be used. This specifically affects the verification of assertion that have been signed.
References and upstream commits:
https://github.com/IdentityPython/pysaml2/commit/5e9d5acbcd8ae45c4e736ac521fd2df5b1c62e25
https://github.com/IdentityPython/pysaml2/commit/f27c7e7a7010f83380566a219fd6a290a00f2b6e
Discussion:
Created python-pysaml2 tracking bugs for t
Bugzilla
CVE-2020-5390 python-pysaml2: does not check that the signature in a SAML document is enveloped [fedora-all]
bugzilla·2020-01-24·CVSS 7.5
CVE-2020-5390 [HIGH] CVE-2020-5390 python-pysaml2: does not check that the signature in a SAML document is enveloped [fedora-all]
CVE-2020-5390 python-pysaml2: does not check that the signature in a SAML document is enveloped [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affe
arXiv
XML Signature Wrapping Still Considered Harmful: A Case Study on the Personal Health Record in Germany
arxiv_fulltext·2021-06-19
XML Signature Wrapping Still Considered Harmful: A Case Study on the Personal Health Record in Germany
XML Signature Wrapping Still Considered Harmful: A Case Study on the Personal Health Record in Germany
XML Signature Wrapping Still Considered Harmful
Paul Höller1 0000-0002-1049-5794
Alexander Krumeich10000-0002-6523-4890
Luigi Lo Iacono20000-0002-7863-0622
n-design GmbH Cologne, Germany
\paul.hoeller, alexander.krumeich\@n-design.de
H-BRS University of Applied Sciences, Sankt Augustin, Germany [email protected]
## Abstract
XML Signature Wrapping (XSW) has been a relevant threat to web services for 15 years until today. Using the Personal Health Record (PHR), which is currently under development in Germany, we investigate a current SOAP-based web services system as a case study. In doing so, we highlight several deficiencies in defending against XSW. Using this real-world cont
https://github.com/IdentityPython/pysaml2/commit/5e9d5acbcd8ae45c4e736ac521fd2df5b1c62e25https://github.com/IdentityPython/pysaml2/commit/f27c7e7a7010f83380566a219fd6a290a00f2b6ehttps://github.com/IdentityPython/pysaml2/releaseshttps://github.com/IdentityPython/pysaml2/releases/tag/v5.0.0https://lists.debian.org/debian-lts-announce/2020/02/msg00025.htmlhttps://pypi.org/project/pysaml2/5.0.0/https://usn.ubuntu.com/4245-1/https://www.debian.org/security/2020/dsa-4630https://github.com/IdentityPython/pysaml2/commit/5e9d5acbcd8ae45c4e736ac521fd2df5b1c62e25https://github.com/IdentityPython/pysaml2/commit/f27c7e7a7010f83380566a219fd6a290a00f2b6ehttps://github.com/IdentityPython/pysaml2/releaseshttps://github.com/IdentityPython/pysaml2/releases/tag/v5.0.0https://lists.debian.org/debian-lts-announce/2020/02/msg00025.htmlhttps://pypi.org/project/pysaml2/5.0.0/https://usn.ubuntu.com/4245-1/https://www.debian.org/security/2020/dsa-4630
2020-01-13
Published