DescriptionPySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object that is signed can be in different places and thus the signature verification will succeed, but the wrong data will be used. This specifically affects the verification of assertion that have been signed.
Overall state of this security issue: Pending
This issue is currently rated as having moderate severity.
|National Vulnerability Database|
|National Vulnerability Database||SUSE|
Status of this issue by product and package
Please note that this evaluation state might be work in progress, incomplete or outdated. Also information for service packs in the LTSS phase is only included for issues meeting the LTSS criteria. If in doubt, feel free to contact us for clarification.
|HPE Helion OpenStack 8||python-pysaml2||Affected|
|SUSE Openstack Cloud 6||python-pysaml2||Affected|
|SUSE Openstack Cloud 7||python-pysaml2||Affected|
|SUSE Openstack Cloud 8||python-pysaml2||Affected|
|SUSE Openstack Cloud 9||python-pysaml2||Affected|