python-pysaml2: Reuse of AES initialization vector in AESCipher
Published Nov 17, 2017
6.3
MEDIUMCVSS 4.0
EPSS 0.89%
Description
Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data.
Affected products
No data.
- < 4.6.0
No data.
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)
python-pysaml2
Will not fix
Red Hat OpenStack Platform 10 (Newton)
python-pysaml2
Will not fix
Red Hat OpenStack Platform 11 (Ocata)
python-pysaml2
Will not fix
Red Hat OpenStack Platform 12 (Pike)
python-pysaml2
Will not fix
Red Hat OpenStack Platform 8 (Liberty)
python-pysaml2
Will not fix
Red Hat OpenStack Platform 9 (Mitaka)
python-pysaml2
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | python-pysaml2 | Will not fix | n/a |
| Red Hat OpenStack Platform 10 (Newton) | python-pysaml2 | Will not fix | n/a |
| Red Hat OpenStack Platform 11 (Ocata) | python-pysaml2 | Will not fix | n/a |
| Red Hat OpenStack Platform 12 (Pike) | python-pysaml2 | Will not fix | n/a |
| Red Hat OpenStack Platform 8 (Liberty) | python-pysaml2 | Will not fix | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | python-pysaml2 | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security has rated this issue as having security impact of Low for: * Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 * Red Hat OpenStack Platform 8.0 (Liberty) * Red Hat OpenStack Platform 9.0 (Mitaka) * Red Hat OpenStack Platform 10.0 (Newton) * Red Hat OpenStack Platform 11.0 (Ocata) * Red Hat OpenStack Platform 12.0 (Pike) Although the affected code is present in shipped packages, python-pysaml2 is included only as a dependency of other packages. The affected code cannot be reached in any supported configuration of Red Hat OpenStack Platform. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
References (8)
- https://access.redhat.com/security/cve/CVE-2017-1000246 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1524420 Issue Tracking
- https://github.com/IdentityPython/pysaml2/pull/519/commits/7323f5c20efb59424d853c822e7a26d1aa3e84aa
- https://github.com/advisories/GHSA-cq94-qf6q-mf2h Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/pysaml2/PYSEC-2017-26.yaml
- https://github.com/rohe/pysaml2/issues/417 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000246
- https://www.cve.org/CVERecord?id=CVE-2017-1000246
Change history (0)
No recorded changes yet.