PT-2018-5207 · Python+1 · Pysaml2+1

Publicado

2018-01-02

·

Atualizado

2021-03-04

·

CVE-2017-1000433

CVSS v4.0

9.2

Crítica

VetorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions pysaml2 versions 4.4.0 and older
Description The issue allows attackers to log in as any user without knowing their password when pysaml2 is run with python optimizations enabled. This is due to the acceptance of any password in affected versions.
Recommendations For pysaml2 versions 4.4.0 and older, consider disabling python optimizations as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-1000433
DLA-1410-1
DLA-2577-1
GHSA-924M-4PMX-C67H
PYSEC-2018-48
SUSE-SU-2018:1194-1
SUSE-SU-2019:1450-1
USN-3520-1

Produtos afetados

Ubuntu
Pysaml2