Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-924m-4pmx-c67h

Опубликовано: 13 июл. 2018
Источник: github
Github: Прошло ревью
CVSS4: 9.2
CVSS3: 8.1

Описание

pysaml2 Improper Authentication vulnerability

pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.

Пакеты

Наименование

pysaml2

pip
Затронутые версииВерсия исправления

< 4.5.0

4.5.0

EPSS

Процентиль: 84%
0.02083
Низкий

9.2 Critical

CVSS4

8.1 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 8 лет назад

pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.

CVSS3: 6.5
redhat
больше 8 лет назад

pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.

CVSS3: 8.1
nvd
около 8 лет назад

pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.

CVSS3: 8.1
debian
около 8 лет назад

pysaml2 version 4.4.0 and older accept any password when run with pyth ...

EPSS

Процентиль: 84%
0.02083
Низкий

9.2 Critical

CVSS4

8.1 High

CVSS3

Дефекты

CWE-287