Описание
PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| python-pysaml2 | unfixed | package |
Примечания
https://github.com/rohe/pysaml2/issues/366
A proper fix for this issue would be to fix the underlying issue in src:libxml2
https://bugzilla.redhat.com/show_bug.cgi?id=1411794#c12
https://www.openwall.com/lists/oss-security/2017/01/19/5 (for the scope of the CVE)
EPSS
Процентиль: 64%
0.00471
Низкий
Связанные уязвимости
CVSS3: 9
ubuntu
почти 9 лет назад
PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.
CVSS3: 7.3
redhat
около 9 лет назад
PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.
CVSS3: 9
nvd
почти 9 лет назад
PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.
EPSS
Процентиль: 64%
0.00471
Низкий