PT-2018-5207 · Python+1 · Pysaml2+1

Published

2018-01-02

·

Updated

2021-03-04

·

CVE-2017-1000433

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions pysaml2 versions 4.4.0 and older
Description The issue allows attackers to log in as any user without knowing their password when pysaml2 is run with python optimizations enabled. This is due to the acceptance of any password in affected versions.
Recommendations For pysaml2 versions 4.4.0 and older, consider disabling python optimizations as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-1000433
DLA-1410-1
DLA-2577-1
GHSA-924M-4PMX-C67H
PYSEC-2018-48
SUSE-SU-2018:1194-1
SUSE-SU-2019:1450-1
USN-3520-1

Affected Products

Ubuntu
Pysaml2