QID 981178

QID 981178: Python (pip) Security Update for pysaml2 (GHSA-924m-4pmx-c67h)

pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to refer to GHSA-924m-4pmx-c67h for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981178

    Software Advisories
    Advisory ID Software Component Link
    GHSA-924m-4pmx-c67h pysaml2 URL Logo github.com/advisories/GHSA-924m-4pmx-c67h