ZeroHour

CVE-2017-1000246

CVSS 3.0
5.3 medium
EPSS
<1%p58
Published
()
Modified
Description

Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data.

Vendors
pysaml2 project
Products
pysaml2
Weakness
CWE-330
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.