Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data.
{ "binaries": [ { "binary_version": "3.0.0-3ubuntu1.16.04.4+esm1", "binary_name": "python-pysaml2" }, { "binary_version": "3.0.0-3ubuntu1.16.04.4+esm1", "binary_name": "python3-pysaml2" } ] }
{ "binaries": [ { "binary_version": "4.0.2-0ubuntu3.2", "binary_name": "python-pysaml2" }, { "binary_version": "4.0.2-0ubuntu3.2", "binary_name": "python3-pysaml2" } ] }