VDB
Sign up
—

PYSEC-2017-25

Quick fix

PYSEC-2017-25 — pysaml2: upgrade to the fixed version with the command below.

pip install --upgrade 'pysaml2>=6e09a25d9b4b7aa7a506853210a9a14100b8bc9b'

Details

XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/pysaml2
Introduced in: 0Fixed in: 6e09a25d9b4b7aa7a506853210a9a14100b8bc9b
Fixpip install --upgrade 'pysaml2>=6e09a25d9b4b7aa7a506853210a9a14100b8bc9b'

References