Executive brief
Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data.
Affected products
- PyPI pysaml2
Junglewise Threat Intelligence
CVE-2017-1000246 · Severity: low · CVSS 3 · Published 2017-11-17
Technologies: pysaml2 (PyPI). Vendors: PyPI.
Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data.