PySAML2 before version 6.5.0 contains an improper verification of cryptographic signature vulnerability in its default CryptoBackendXmlSec1 backend. When verifying signed SAML documents, the backend relies on the xmlsec1 binary, which by default accepts any key type present in the document for signature verification. This allows an attacker to craft a SAML document with a non-x509 key, potentially bypassing signature validation and leading to acceptance of forged SAML assertions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a minimal proof-of-concept for CVE-2021-21239 affecting xmlsec (xmlsec1). Structure: (1) Dockerfile builds an Alpine-based environment, compiles and installs xmlsec1-1.2.25 from source, and generates an RSA private key (/root/key.pem). (2) cve-2021-21239.py is the main PoC: it accepts a base64-encoded XML string, decodes it, performs regex-based modifications to signature-related elements/attributes (empties ds:Value content, blanks URI attributes, replaces ds:X509Data with <KeyValue/>), writes the result to req.xml, then calls the local xmlsec1 CLI to sign the XML using key.pem. It outputs the signed XML as a single-line base64 string. (3) README.md briefly describes usage and links to upstream xmlsec discussion. No network exploitation logic, scanning, or remote callback endpoints are present; the PoC is intended to demonstrate signature processing behavior/weakness by producing a crafted, signed XML artifact.
This repository contains a working exploit for CVE-2021-21239, a SAML signature validation bypass in pysaml2 (<6.5.0) as used by Redash (<=10.1.0). The exploit is implemented in 'cve-2021-21239.py', a Python script that forges a SAML response with an attacker-controlled public key, signs it, and submits it to the Redash SAML callback endpoint. The script automates the process of filling an XML template ('SAMLResponseTempalte.xml') with attacker-supplied user attributes, generating a new RSA key pair, signing the assertion, and sending the response to the target Redash instance. If successful, the attacker receives a valid session cookie for the impersonated user and can enumerate users and their groups. The repository also includes a detailed README.md explaining the vulnerability, exploitation steps, and technical background. The exploit is operational and demonstrates privilege escalation and user impersonation on vulnerable Redash instances configured with SAML SSO.
This repository provides a full exploit environment and proof-of-concept for CVE-2021-21239, a SAML authentication bypass in Redash via pysaml2 <= 6.4.1 and xmlsec1. The structure includes Docker Compose files to spin up a vulnerable Redash instance, Bash scripts for environment setup and server management, and a Python exploit (poc.py) that forges a malicious SAML response with an embedded RSA key. The exploit leverages the fact that xmlsec1, when called without the --enabled-key-data flag, will prefer embedded keys over configured certificates, allowing an attacker to authenticate as any user. The main exploit script (poc.py) generates a keypair, crafts a SAML response, signs it, and submits it to the Redash SAML endpoint, resulting in the creation and login of an attacker-controlled user. The repository is well-documented, with a README and a POC walkthrough, and is intended for security research and demonstration of the vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.