Insecure generation of random numbers In python-pysaml2
Description
Pysaml2 improperly initializes encryption vector Python package pysaml2 version 4.5.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 4.5.0-4 | ||
debian 11 | 4.5.0-4 | ||
debian 13 | 4.5.0-4 | ||
pypi | 4.6.0 | ||
debian 14 | 4.5.0-4 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3.