QID 981143
QID 981143: Python (pip) Security Update for pysaml2 (GHSA-c2vx-49jm-h3f6)
XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-c2vx-49jm-h3f6 for updates pertaining to this vulnerability.
Vendor References
- GHSA-c2vx-49jm-h3f6 -
github.com/advisories/GHSA-c2vx-49jm-h3f6
CVEs related to QID 981143
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-c2vx-49jm-h3f6 | pysaml2 |
|