445
VMScore

CVE-2016-10149

Published: 24/03/2017 Updated: 05/01/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and previous versions allows remote malicious users to read arbitrary files via a crafted SAML XML request or response.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pysaml2 project pysaml2

debian debian linux 8.0

Vendor Advisories

Debian Bug report logs - #850716 python-pysaml2: CVE-2016-10149 Package: src:python-pysaml2; Maintainer for src:python-pysaml2 is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Thomas Goirand <zigo@debianorg> Date: Mon, 9 Jan 2017 15:30:05 UTC Severity: serious Tags: patch, security, upstream F ...
The system could be made to expose sensitive information ...
Matias P Brutti discovered that python-pysaml2, a Python implementation of the Security Assertion Markup Language 20, did not correctly sanitize the XML messages it handled This allowed a remote attacker to perform XML External Entity attacks, leading to a wide range of exploits For the stable distribution (jessie), this problem has been fixed ...
Synopsis Moderate: python-defusedxml and python-pysaml2 security update Type/Severity Security Advisory: Moderate Topic An update for python-defusedxml and python-pysaml2 is now available for Red Hat OpenStack Platform 80 (Liberty)Red Hat Product Security has rated this update as having a security impact ...
Synopsis Moderate: python-defusedxml and python-pysaml2 security update Type/Severity Security Advisory: Moderate Topic An update for python-defusedxml and python-pysaml2 is now available for Red Hat OpenStack Platform 90 (Mitaka)Red Hat Product Security has rated this update as having a security impact o ...
Synopsis Moderate: python-defusedxml and python-pysaml2 security update Type/Severity Security Advisory: Moderate Topic An update for python-defusedxml and python-pysaml2 is now available for Red Hat OpenStack Platform 100 (Newton)Red Hat Product Security has rated this update as having a security impact ...
An XML entity expansion vulnerability was found in python-pysaml2 A remote attacker could send a crafted request which would cause denial of service through resource exhaustion ...