—
PYSEC-2018-48
Quick fix
PYSEC-2018-48 — pysaml2: upgrade to the fixed version with the command below.
pip install --upgrade 'pysaml2>=4.5.0'Details
pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/rohe/pysaml2/issues/451[REPORT]
- https://security.gentoo.org/glsa/201801-11[ADVISORY]
- https://lists.debian.org/debian-lts-announce/2018/07/msg00000.html[WEB]
- https://lists.debian.org/debian-lts-announce/2021/02/msg00038.html[WEB]
- https://github.com/advisories/GHSA-924m-4pmx-c67h[ADVISORY]