Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data.
{ "binaries": [ { "binary_name": "python-pysaml2", "binary_version": "3.0.0-3ubuntu1.16.04.4+esm1" }, { "binary_name": "python3-pysaml2", "binary_version": "3.0.0-3ubuntu1.16.04.4+esm1" } ] }
{ "binaries": [ { "binary_name": "python-pysaml2", "binary_version": "4.0.2-0ubuntu3.2" }, { "binary_name": "python3-pysaml2", "binary_version": "4.0.2-0ubuntu3.2" } ] }