Vulnerabilities > Pysaml2 Project > Pysaml2 > 4.5.0

DATE CVE VULNERABILITY TITLE RISK
2021-01-21 CVE-2021-21239 PySAML2 is a pure python implementation of SAML Version 2 Standard.
network
low complexity
pysaml2-project debian
6.5
2021-01-21 CVE-2021-21238 Unspecified vulnerability in Pysaml2 Project Pysaml2
PySAML2 is a pure python implementation of SAML Version 2 Standard.
network
low complexity
pysaml2-project
6.5
2020-01-13 CVE-2020-5390 Improper Verification of Cryptographic Signature vulnerability in multiple products
PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW).
network
low complexity
pysaml2-project canonical debian CWE-347
7.5
2017-11-17 CVE-2017-1000246 Use of Insufficiently Random Values vulnerability in Pysaml2 Project Pysaml2
Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data.
network
low complexity
pysaml2-project CWE-330
5.3