Junglewise Threat Intelligence

CVE-2017-1000246: PYSEC-2017-26 - Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak en

CVE-2017-1000246 · Severity: low · CVSS 3 · Published 2017-11-17

Technologies: pysaml2 (PyPI). Vendors: PyPI.

Executive brief

Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data.

Affected products

  • PyPI pysaml2

Related threats