Pysaml2 · Pysaml2 · CVE-2016-10149
**Name of the Vulnerable Software and Affected Versions**
PySAML2 versions 4.4.0 and earlier
**Description**
The issue allows remote attackers to read arbitrary files via a crafted SAML XML request or response. This is due to an XML External Entity (XXE) vulnerability.
**Recommendations**
For PySAML2 versions 4.4.0 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.