605
VMScore

CVE-2017-1000433

Published: 02/01/2018 Updated: 04/03/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows malicious users to log in as any user without knowing their password.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pysaml2 project pysaml2

debian debian linux 8.0

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #886423 python-pysaml2: CVE-2017-1000433: Access restriction bypass Package: src:python-pysaml2; Maintainer for src:python-pysaml2 is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 5 Jan 2018 19:54:04 UTC Severity: impor ...
PySAML2 could allow authentication without a password ...
pysaml2 version 440 and older accept any password when run with python optimizations enabled This allows attackers to log in as any user without knowing their password ...