Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Fruechel

#14886of 53,633
18.1Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2017-7752
9.4
2017-01-12
Pysaml2 · Pysaml2 · CVE-2016-10127
**Name of the Vulnerable Software and Affected Versions** PySAML2 (affected versions not specified) **Description** The issue allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2017-7771
8.7
2017-01-12
Pysaml2 · Pysaml2 · CVE-2016-10149
**Name of the Vulnerable Software and Affected Versions** PySAML2 versions 4.4.0 and earlier **Description** The issue allows remote attackers to read arbitrary files via a crafted SAML XML request or response. This is due to an XML External Entity (XXE) vulnerability. **Recommendations** For PySAML2 versions 4.4.0 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.