Executive brief
PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.
Affected products
- PyPI pysaml2
Junglewise Threat Intelligence
CVE-2016-10127 · Severity: low · CVSS 3 · Published 2017-03-03
Technologies: pysaml2 (PyPI). Vendors: PyPI.
PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.