CVE-2021-21239
CVE-2021-21239 — Open default xmlsec1 key-type preference
PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. Users of pysaml2 that use the default CryptoBackendXmlSec1 backend and need to verify signed SAML documents are impacted. PySAML2 does not ensure that a signed SAML document is correctly signed. The default CryptoBackendXmlSec1 backend is using the xmlsec1 binary to verify the signature of signed SAML documents, but by default xmlsec1 accepts any type of key found within the given document. xmlsec1 needs to be configured explicitly to only use only _x509 certificates_ for the verification process of the SAML document signature. This is fixed in PySAML2 6.5.0.
Published Updated Sources: cvelistV5, GitHub_M
Triage
Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.
Exploitation
Exploit code
public exploit, none observed
EPSS
1%
chance of exploitation in 30 days
CVSS base
6.5
MEDIUM
Affected scope
The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.
Vendors (1)
Products (1)
Every base score collected
Sources score independently and disagree; each row says who scored it and under which version.
| Score | Version | Severity | Expl. | Impact | Source |
|---|---|---|---|---|---|
| 6.5 | CVSS 3.1 | MEDIUM | — | — | cvelistV5 |
Weakness & attack patterns
- CWE-347
Public exploit
Capability, not use: code existing is a different claim from anyone running it.
Indexed by
References
6 on the record
- github.com/IdentityPython/pysaml2/security/advisories/GHSA-5p3x-r448-pc62
x_refsource_CONFIRM
- pypi.org/project/pysaml2
x_refsource_MISC
- www.aleksey.com/pipermail/xmlsec/2013/009717.html
x_refsource_MISC
- github.com/IdentityPython/pysaml2/releases/tag/v6.5.0
x_refsource_MISC
- github.com/IdentityPython/pysaml2/commit/46578df0695269a16f1c94171f1429873f90ed99
x_refsource_MISC
- lists.debian.org/debian-lts-announce/2021/02/msg00038.html
mailing-list, x_refsource_MLIST
Elsewhere on this site
- identitypythonevery CVE for this vendor
- CWE-347other pages naming this weakness
Not in any source we poll
Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.
- No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
- No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
- No exploit packet captures, log samples, or incident case IDs supplied.