Get a Pentest and security assessment of your IT network.

2021-current

CVE-2020-26244 – Python oic is a Python OpenID Connect implementation. In Python oic befor

Python oic is a Python OpenID Connect implementation. In Python oic before version 1.2.1, there are several related cryptographic issues affecting client implementations that use the library. The issues are: 1) The IdToken signature algorithm was not checked automatically, but only if the expected algorithm was passed in as a kwarg. 2) JWA `none` algorithm was allowed in all flows. 3) oic.consumer.Consumer.parse_authz returns an unverified IdToken. The verification of the token was left to the discretion of the implementator. 4) iat claim was not checked for sanity (i.e. it could be in the future). These issues are patched in version 1.2.1.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26244

Reference (s):

  • https://github.com/OpenIDC/pyoidc/security/advisories/GHSA-4fjv-pmhg-3rfg
  • URL: https://github.com/OpenIDC/pyoidc/security/advisories/GHSA-4fjv-pmhg-3rfg
  • https://github.com/OpenIDC/pyoidc/commit/62f8d753fa17c8b1f29f8be639cf0b33afb02498
  • URL: https://github.com/OpenIDC/pyoidc/commit/62f8d753fa17c8b1f29f8be639cf0b33afb02498
  • https://github.com/OpenIDC/pyoidc/releases/tag/1.2.1
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-5418 - GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2

2021-current

CVE-2019-7127 - Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20

2021-current

CVE-2020-10978 - GitLab EE/CE 8.11 to 12.9 is leaking information on Issues opened in a pu