-
Notifications
You must be signed in to change notification settings - Fork 145
Closed
Description
Safety report (pyup.io):
[
[
"pysaml2",
"<=4.4.0",
"4.4.0",
"pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.",
"35700"
],
[
"pysaml2",
"<=4.4.0",
"4.4.0",
"Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data.",
"35699"
]
]
EDIT: there is related PR #114
Metadata
Metadata
Assignees
Labels
No labels