VDB
Sign up
—

PYSEC-2017-67

Quick fix

PYSEC-2017-67 — pysaml2: upgrade to the fixed version with the command below.

pip install --upgrade 'pysaml2>=6e09a25d9b4b7aa7a506853210a9a14100b8bc9b'

Details

PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/pysaml2
Introduced in: 0Fixed in: 6e09a25d9b4b7aa7a506853210a9a14100b8bc9b
Fixpip install --upgrade 'pysaml2>=6e09a25d9b4b7aa7a506853210a9a14100b8bc9b'

References