pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade python-pysaml2 | Feb 19, 2019 | Jan 2, 2018 |
| Gentoo Linux | — | Upgrade dev-python/pysaml2. | Jan 12, 2018 | Jan 2, 2018 |
| Ubuntu | — | Upgrade python-pysaml2Upgrade python3-pysaml2 | Jan 9, 2018 | Jan 2, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub