XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.
| Score | Percentile |
|---|---|
| 1.31% | 79.52% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 7.5 | 3.0 | — |
|
| 8.7 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-c2vx-49jm-h3f6 ↗ |
| CVE | CVE-2016-10149 ↗ |
| CWE id | Name |
|---|---|
| CWE-611 | Improper Restriction of XML External Entity Reference |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| pip | pysaml2 | <= 4.4.0 | 4.5.0 | — |