Junglewise Threat Intelligence

CVE-2016-10127: PYSEC-2017-67 - PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.

CVE-2016-10127 · Severity: low · CVSS 3 · Published 2017-03-03

Technologies: pysaml2 (PyPI). Vendors: PyPI.

Executive brief

PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.

Affected products

  • PyPI pysaml2

Related threats