[Openstack-security] [Bug 1750843] Re: pysaml2 version in global requirements must be updated to 4.5.0
Lance Bragstad
lbragstad at gmail.com
Thu Mar 29 21:14:55 UTC 2018
Given the comments from the keystone team, I'm going to mark this as Low
for the time being. The patch Matt linked in comment #11 also passed
when depending on a bump of pysaml2 to version 4.5.0.
>From a keystone perspective, we should be able to close this once the
OpenStack Proposal Bot proposes an update of pysaml2 to keystone's
requirements file.
** Changed in: keystone
Status: New => Confirmed
** Changed in: keystone
Importance: Undecided => Low
--
You received this bug notification because you are a member of OpenStack
Security SIG, which is subscribed to OpenStack.
https://bugs.launchpad.net/bugs/1750843
Title:
pysaml2 version in global requirements must be updated to 4.5.0
Status in OpenStack Identity (keystone):
Confirmed
Status in OpenStack Global Requirements:
New
Bug description:
As per security vulnerability CVE-2016-10149, XML External Entity
(XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote
attackers to read arbitrary files via a crafted SAML XML request or
response and it has a CVSS v3 Base Score of 7.5.
The above vulnerability has been fixed in version 4.5.0 as per
https://github.com/rohe/pysaml2/issues/366. The latest version of
pysaml2 (https://pypi.python.org/pypi/pysaml2/4.5.0) has this fix.
However, the global requirements has the version set to < 4.0.3
https://github.com/openstack/requirements/blob/master/global-requirements.txt#L230
pysaml2>=4.0.2,<4.0.3
https://github.com/openstack/requirements/blob/master/upper-constraints.txt#L347
pysaml2===4.0.2
The version of pysaml2 supported for OpenStack should be updated such
that OpenStack deployments are not vulnerable to the above mentioned
CVE.
pysaml2 is used by OpenStack Keystone for identity Federation. This
bug in itself is not a security vulnerability but not fixing this bug
causes OpenStack deployments to be vulnerable.
To manage notifications about this bug go to:
https://bugs.launchpad.net/keystone/+bug/1750843/+subscriptions
More information about the Openstack-security
mailing list