Ipsilon denial of service via a duplicate SP name

Description

providers/saml2/admin.py in the Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not properly check permissions to update the SAML2 Service Provider (SP) owner, which allows remote authenticated users to cause a denial of service via a duplicate SP name.

Basic information

Type
reviewed
Severity
medium
Advisory on GitHub
Open advisory ↗
Repository advisory
Source code
Browse source ↗
Published (advisory)
2022-05-17 04:01:58 UTC
Updated
2024-11-22 20:20:14 UTC
GitHub reviewed
2024-11-22 20:20:12 UTC
NVD published
2015-11-17

EPSS Score

Score Percentile
0.39% 59.51%

CVSS Scores

No CVSS scores in this advisory.

Identifiers

Affected packages (1)

Vulnerable version ranges and first patched releases as published by GitHub.

Ecosystem Package Vulnerable range First patched Vulnerable functions
pip ipsilon >= 0.1.0, < 1.0.1 1.2.0

References

cvelogic Threat Intelligence