Описание
XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.
An XML entity expansion vulnerability was found in python-pysaml2. A remote attacker could send a crafted request which would cause denial of service through resource exhaustion.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | python-pysaml2 | Will not fix | ||
| Red Hat OpenStack Platform 11 (Ocata) | python-pysaml2 | Not affected | ||
| Red Hat OpenStack Platform 10.0 (Newton) | python-defusedxml | Fixed | RHSA-2017:0938 | 12.04.2017 |
| Red Hat OpenStack Platform 10.0 (Newton) | python-pysaml2 | Fixed | RHSA-2017:0938 | 12.04.2017 |
| Red Hat OpenStack Platform 8.0 (Liberty) | python-defusedxml | Fixed | RHSA-2017:0936 | 12.04.2017 |
| Red Hat OpenStack Platform 8.0 (Liberty) | python-pysaml2 | Fixed | RHSA-2017:0936 | 12.04.2017 |
| Red Hat OpenStack Platform 9.0 (Mitaka) | python-defusedxml | Fixed | RHSA-2017:0937 | 12.04.2017 |
| Red Hat OpenStack Platform 9.0 (Mitaka) | python-pysaml2 | Fixed | RHSA-2017:0937 | 12.04.2017 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.
XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.
XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier a ...
EPSS
5.3 Medium
CVSS3