Description
pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1410-1 | python-pysaml2 security update |
Debian DLA |
DLA-2577-1 | python-pysaml2 security update |
EUVD |
EUVD-2018-0126 | pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password. |
Github GHSA |
GHSA-924m-4pmx-c67h | pysaml2 Improper Authentication vulnerability |
Ubuntu USN |
USN-3520-1 | PySAML2 vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T22:00:41.084Z
Reserved: 2018-01-02T00:00:00.000Z
Link: CVE-2017-1000433
No data.
Status : Modified
Published: 2018-01-02T23:29:00.337
Modified: 2024-11-21T03:04:44.003
Link: CVE-2017-1000433
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA
Ubuntu USN