Vulnerability Name: | CVE-2020-26244 (CCN-192561) | ||||||||||||
Assigned: | 2020-12-01 | ||||||||||||
Published: | 2020-12-01 | ||||||||||||
Updated: | 2020-12-08 | ||||||||||||
Summary: | Python oic is a Python OpenID Connect implementation. In Python oic before version 1.2.1, there are several related cryptographic issues affecting client implementations that use the library. The issues are: 1) The IdToken signature algorithm was not checked automatically, but only if the expected algorithm was passed in as a kwarg. 2) JWA `none` algorithm was allowed in all flows. 3) oic.consumer.Consumer.parse_authz returns an unverified IdToken. The verification of the token was left to the discretion of the implementator. 4) iat claim was not checked for sanity (i.e. it could be in the future). These issues are patched in version 1.2.1. | ||||||||||||
CVSS v3 Severity: | 6.8 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N) 5.9 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C)
7.1 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.9 Medium (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N)
| ||||||||||||
Vulnerability Type: | CWE-347 | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-26244 Source: XF Type: UNKNOWN pythonoic-cve202026244-sec-bypass(192561) Source: MISC Type: Patch, Third Party Advisory https://github.com/OpenIDC/pyoidc/commit/62f8d753fa17c8b1f29f8be639cf0b33afb02498 Source: MISC Type: Third Party Advisory https://github.com/OpenIDC/pyoidc/releases/tag/1.2.1 Source: CCN Type: Python oic GIT Repository Client vulnerabilites to replay attack and cipher downgrade Source: CONFIRM Type: Third Party Advisory https://github.com/OpenIDC/pyoidc/security/advisories/GHSA-4fjv-pmhg-3rfg Source: MISC Type: Product, Vendor Advisory https://pypi.org/project/oic/ | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |