Описание
PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| python-pysaml2 | unfixed | package |
Примечания
https://github.com/rohe/pysaml2/issues/366
A proper fix for this issue would be to fix the underlying issue in src:libxml2
https://bugzilla.redhat.com/show_bug.cgi?id=1411794#c12
https://www.openwall.com/lists/oss-security/2017/01/19/5 (for the scope of the CVE)
EPSS
Процентиль: 80%
0.02133
Низкий
Связанные уязвимости
CVSS3: 9
ubuntu
больше 9 лет назад
PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.
CVSS3: 7.3
redhat
больше 9 лет назад
PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.
CVSS3: 9
nvd
больше 9 лет назад
PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.
EPSS
Процентиль: 80%
0.02133
Низкий