CVE-2020-5390
python-pysaml2 - security update
7.5
HIGH
CVSS 3.1
EPSS 1.2%
描述
PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object that is signed can be in different places and thus the signature verification will succeed, but the wrong data will be used. This specifically affects the verification of assertion that have been signed.
如何修補 CVE-2020-5390
要修補 CVE-2020-5390,請將受影響套件升級到下列已修補版本。
- —升級至 4.5.0-7 或更新版本
- —升級至 2.0.0-1+deb8u3 或更新版本
- —升級至 3.0.0-5+deb9u1 或更新版本
- —升級至 5.0.0 或更新版本
- —升級至 f27c7e7a7010f83380566a219fd6a290a00f2b6e 或更新版本
CVE-2020-5390 正在被利用嗎?
低 — EPSS 為 1.2%,目前沒有觀察到大規模利用活動。
受影響套件(5)
- from 0, < 4.5.0-7
- from 0, < 2.0.0-1+deb8u3
- from 0, < 3.0.0-5+deb9u1
- from 0, < 5.0.0
- from 0, < f27c7e7a7010f83380566a219fd6a290a00f2b6e, < 5e9d5acbcd8ae45c4e736ac521fd2df5b1c62e25 | from 0, < 5.0.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |