Rapid7 Vulnerability & Exploit Database

Ubuntu: USN-4245-1 (CVE-2020-5390): PySAML2 vulnerability

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

Ubuntu: USN-4245-1 (CVE-2020-5390): PySAML2 vulnerability

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
Published
01/13/2020
Created
01/23/2020
Added
01/22/2020
Modified
03/22/2023

Description

PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object that is signed can be in different places and thus the signature verification will succeed, but the wrong data will be used. This specifically affects the verification of assertion that have been signed.

Solution(s)

  • ubuntu-upgrade-python-pysaml2
  • ubuntu-upgrade-python3-pysaml2

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;