4.0.5
10 years ago
5 days ago
Known vulnerabilities in the signxml package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
signxml is a Python XML Signature and XAdES library Affected versions of this package are vulnerable to Timing Attack due to the Note: This is only exploitable if X509 certificate validation is turned off and a specific HMAC shared secret is set. How to fix Timing Attack? Upgrade | [,4.0.4) |
signxml is a Python XML Signature and XAdES library Affected versions of this package are vulnerable to Incorrect Implementation of Authentication Algorithm due to the improper handling of signature verification settings when Note:
This is only exploitable if the user has not explicitly limited the expected signature algorithms using the How to fix Incorrect Implementation of Authentication Algorithm? Upgrade | [,4.0.4) |