CVE-2021-21238
published 2021-01-21CVE-2021-21238: PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability…
PriorityP429medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
1.08%
61.7th percentile
PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. All users of pysaml2 that need to validate signed SAML documents are impacted. The vulnerability is a variant of XML Signature wrapping because it did not validate the SAML document against an XML schema. This allowed invalid XML documents to be processed and such a document can trick pysaml2 with a wrapped signature. This is fixed in PySAML2 6.5.0.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | python-pysaml2 | < python-pysaml2 6.5.1-1 (bookworm) | python-pysaml2 6.5.1-1 (bookworm) |
| identitypython | pysaml2 | < 6.5.0 | 6.5.0 |
| pysaml2_project | pysaml2 | < 6.5.0 | 6.5.0 |
| pysaml2_project | pysaml2 | >= 0 < 6.5.0 | 6.5.0 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2021-21238: PySAML2 is a pure python implementation of SAML Version 2 Standard
osv·2021-01-21·CVSS 6.5
CVE-2021-21238 [MEDIUM] CVE-2021-21238: PySAML2 is a pure python implementation of SAML Version 2 Standard
PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. All users of pysaml2 that need to validate signed SAML documents are impacted. The vulnerability is a variant of XML Signature wrapping because it did not validate the SAML document against an XML schema. This allowed invalid XML documents to be processed and such a document can trick pysaml2 with a wrapped signature. This is fixed in PySAML2 6.5.0.
OSV
SAML XML Signature wrapping in PySAML2
osv·2021-01-21
CVE-2021-21238 [MEDIUM] SAML XML Signature wrapping in PySAML2
SAML XML Signature wrapping in PySAML2
### Impact
All users of pysaml2 that use the default `CryptoBackendXmlSec1` backend and need to verify signed SAML documents are impacted. `pysaml2 <= 6.4.1` does not validate the SAML document against an XML schema. This allows invalid XML documents to trick the verification process, by presenting elements with a valid signature inside elements whose content has been malformed. The verification is offloaded to `xmlsec1` and `xmlsec1` will not validate every signature in the given document, but only the first it finds in the given scope.
### Patches
Users should upgrade to pysaml2 `v6.5.0`.
### Workarounds
No workaround provided at this point.
### References
No references provided at this point.
### Credits
- Victor Schönfelder Garcia (isit
GHSA
SAML XML Signature wrapping in PySAML2
ghsa·2021-01-21
CVE-2021-21238 [MEDIUM] CWE-347 SAML XML Signature wrapping in PySAML2
SAML XML Signature wrapping in PySAML2
### Impact
All users of pysaml2 that use the default `CryptoBackendXmlSec1` backend and need to verify signed SAML documents are impacted. `pysaml2 <= 6.4.1` does not validate the SAML document against an XML schema. This allows invalid XML documents to trick the verification process, by presenting elements with a valid signature inside elements whose content has been malformed. The verification is offloaded to `xmlsec1` and `xmlsec1` will not validate every signature in the given document, but only the first it finds in the given scope.
### Patches
Users should upgrade to pysaml2 `v6.5.0`.
### Workarounds
No workaround provided at this point.
### References
No references provided at this point.
### Credits
- Victor Schönfelder Garcia (isit
Red Hat
python-pysaml2: processing of invalid SAML XML documents
vendor_redhat·2021-01-21·CVSS 6.5
CVE-2021-21238 [MEDIUM] CWE-347 python-pysaml2: processing of invalid SAML XML documents
python-pysaml2: processing of invalid SAML XML documents
PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. All users of pysaml2 that need to validate signed SAML documents are impacted. The vulnerability is a variant of XML Signature wrapping because it did not validate the SAML document against an XML schema. This allowed invalid XML documents to be processed and such a document can trick pysaml2 with a wrapped signature. This is fixed in PySAML2 6.5.0.
A verification flaw was found in python-pysaml2, where it did not validate signed SAML documents against an XML schema. Because the flaw allowed invalid XML documents to be processed, a network attacker could exploit this flaw by
Debian
CVE-2021-21238: python-pysaml2 - PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 befo...
vendor_debian·2021·CVSS 6.5
CVE-2021-21238 [MEDIUM] CVE-2021-21238: python-pysaml2 - PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 befo...
PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. All users of pysaml2 that need to validate signed SAML documents are impacted. The vulnerability is a variant of XML Signature wrapping because it did not validate the SAML document against an XML schema. This allowed invalid XML documents to be processed and such a document can trick pysaml2 with a wrapped signature. This is fixed in PySAML2 6.5.0.
Scope: local
bookworm: resolved (fixed in 6.5.1-1)
bullseye: resolved (fixed in 6.5.1-1)
forky: resolved (fixed in 6.5.1-1)
sid: resolved (fixed in 6.5.1-1)
trixie: resolved (fixed in 6.5.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/IdentityPython/pysaml2/commit/1d8fd268f5bf887480a403a7a5ef8f048157cc14https://github.com/IdentityPython/pysaml2/releases/tag/v6.5.0https://github.com/IdentityPython/pysaml2/security/advisories/GHSA-f4g9-h89h-jgv9https://pypi.org/project/pysaml2https://github.com/IdentityPython/pysaml2/commit/1d8fd268f5bf887480a403a7a5ef8f048157cc14https://github.com/IdentityPython/pysaml2/releases/tag/v6.5.0https://github.com/IdentityPython/pysaml2/security/advisories/GHSA-f4g9-h89h-jgv9https://pypi.org/project/pysaml2
2021-01-21
Published