Executive brief
XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.
Affected products
- PyPI pysaml2
Junglewise Threat Intelligence
CVE-2016-10149 · Severity: low · CVSS 3 · Published 2017-03-24
Technologies: pysaml2 (PyPI). Vendors: PyPI.
XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.