Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data.
{
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:pysaml2_project:pysaml2:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "4.6.0"
}
]
}