UbuntuUpdates.org

Package "python3-lasso"

Name: python3-lasso

Description:

Library for Liberty Alliance and SAML protocols - Python bindings

Latest version: 2.6.0-7ubuntu1.2
Release: focal (20.04)
Level: security
Repository: universe
Head package: lasso
Homepage: http://lasso.entrouvert.org

Links


Download "python3-lasso"


Other versions of "python3-lasso" in Focal

Repository Area Version
base universe 2.6.0-7ubuntu1
updates universe 2.6.0-7ubuntu1.2

Changelog

Version: 2.6.0-7ubuntu1.2 2021-06-02 05:06:29 UTC

  lasso (2.6.0-7ubuntu1.2) focal-security; urgency=medium

  * SECURITY UPDATE: unsigned assertions after signed valid assertions
    are honored.
    - d/p/CVE-2021-28091.patch: Fix signature checking on unsigned
      response with multiple assertions
    - CVE-2021-28091

 -- Steve Beattie <email address hidden> Fri, 28 May 2021 14:49:51 -0700

CVE-2021-28091 XML signature wrapping vulnerability when parsing SAML responses



About   -   Send Feedback to @ubuntu_updates