Junglewise Threat Intelligence

CVE-2016-10149: PYSEC-2017-25 - XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML

CVE-2016-10149 · Severity: low · CVSS 3 · Published 2017-03-24

Technologies: pysaml2 (PyPI). Vendors: PyPI.

Executive brief

XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.

Affected products

  • PyPI pysaml2

Related threats