
Cloud Vulnerability DB
A community-led vulnerabilities database
PySAML2 versions before 6.5.0 contained a cryptographic signature verification vulnerability (CVE-2021-21239) discovered in January 2021. The vulnerability affected the default CryptoBackendXmlSec1 backend, which is used to verify signatures of SAML documents (GitHub Advisory, NVD).
The vulnerability stems from the default CryptoBackendXmlSec1 backend using the xmlsec1 binary to verify signatures without properly restricting the key types. By default, xmlsec1 accepts any type of key found within the given document, instead of being explicitly configured to only use x509 certificates for SAML document signature verification (GitHub Advisory, Debian LTS).
The vulnerability allows attackers to potentially alter SAML documents by exploiting the improper signature verification. All users of pysaml2 that use the default CryptoBackendXmlSec1 backend and need to verify signed SAML documents are impacted (GitHub Advisory, Ubuntu Notice).
The vulnerability could be exploited by an attacker to manipulate SAML documents due to the improper validation of cryptographic signatures. The issue was rated as Critical severity, indicating a significant security risk (GitHub Advisory).
The vulnerability was patched in PySAML2 version 6.5.0, released on January 20, 2021. Users should upgrade to this version or later to address the security issue. The fix involves explicitly configuring xmlsec1 to only use x509 certificates for the verification process of SAML document signatures (GitHub Release, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."