Vulnerability Details CVE-2021-21238
PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vulnerability. All users of pysaml2 that need to validate signed SAML documents are impacted. The vulnerability is a variant of XML Signature wrapping because it did not validate the SAML document against an XML schema. This allowed invalid XML documents to be processed and such a document can trick pysaml2 with a wrapped signature. This is fixed in PySAML2 6.5.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 34.9%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.3
Products affected by CVE-2021-21238
-
cpe:2.3:a:pysaml2_project:pysaml2:-
-
cpe:2.3:a:pysaml2_project:pysaml2:0.1
-
cpe:2.3:a:pysaml2_project:pysaml2:0.2
-
cpe:2.3:a:pysaml2_project:pysaml2:0.4
-
cpe:2.3:a:pysaml2_project:pysaml2:0.4.1
-
cpe:2.3:a:pysaml2_project:pysaml2:0.4.2
-
cpe:2.3:a:pysaml2_project:pysaml2:0.4.3
-
cpe:2.3:a:pysaml2_project:pysaml2:1.0.0
-
cpe:2.3:a:pysaml2_project:pysaml2:1.0.1
-
cpe:2.3:a:pysaml2_project:pysaml2:1.0.3
-
cpe:2.3:a:pysaml2_project:pysaml2:2.0.0
-
cpe:2.3:a:pysaml2_project:pysaml2:2.1.0
-
cpe:2.3:a:pysaml2_project:pysaml2:2.2.0
-
cpe:2.3:a:pysaml2_project:pysaml2:2.3.0
-
cpe:2.3:a:pysaml2_project:pysaml2:2.4.0
-
cpe:2.3:a:pysaml2_project:pysaml2:3.0.0
-
cpe:2.3:a:pysaml2_project:pysaml2:3.0.2
-
cpe:2.3:a:pysaml2_project:pysaml2:4.0.0
-
cpe:2.3:a:pysaml2_project:pysaml2:4.1.0
-
cpe:2.3:a:pysaml2_project:pysaml2:4.2.0
-
cpe:2.3:a:pysaml2_project:pysaml2:4.3.0
-
cpe:2.3:a:pysaml2_project:pysaml2:4.4.0
-
cpe:2.3:a:pysaml2_project:pysaml2:4.5.0
-
cpe:2.3:a:pysaml2_project:pysaml2:4.6.0
-
cpe:2.3:a:pysaml2_project:pysaml2:4.6.1
-
cpe:2.3:a:pysaml2_project:pysaml2:4.6.2
-
cpe:2.3:a:pysaml2_project:pysaml2:4.6.3
-
cpe:2.3:a:pysaml2_project:pysaml2:4.6.4
-
cpe:2.3:a:pysaml2_project:pysaml2:4.6.5
-
cpe:2.3:a:pysaml2_project:pysaml2:4.7.0
-
cpe:2.3:a:pysaml2_project:pysaml2:4.8.0
-
cpe:2.3:a:pysaml2_project:pysaml2:4.9.0
-
cpe:2.3:a:pysaml2_project:pysaml2:5.0.0
-
cpe:2.3:a:pysaml2_project:pysaml2:5.1.0
-
cpe:2.3:a:pysaml2_project:pysaml2:5.2.0
-
cpe:2.3:a:pysaml2_project:pysaml2:5.3.0
-
cpe:2.3:a:pysaml2_project:pysaml2:5.4.0
-
cpe:2.3:a:pysaml2_project:pysaml2:6.0.0
-
cpe:2.3:a:pysaml2_project:pysaml2:6.1.0
-
cpe:2.3:a:pysaml2_project:pysaml2:6.2.0
-
cpe:2.3:a:pysaml2_project:pysaml2:6.3.0
-
cpe:2.3:a:pysaml2_project:pysaml2:6.3.1
-
cpe:2.3:a:pysaml2_project:pysaml2:6.4.0
-
cpe:2.3:a:pysaml2_project:pysaml2:6.4.1