suse · CVE-2016-10127

Quick triage

Priority: high Published: 2021-05-30 13:49:05 UTC Updated: 2022-11-27 01:29:25 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-10127 severity important: SUSE including 166 source package names (ardana-ansible-8.0+git.1566374355.c509923-3.67.3, ardana-glance-8.0+git.1566376789.be0fe01-3.17.3, …), 347 product×package rows across 6 product lines (HPE Helion OpenStack 8, SUSE Enterprise Storage 4, … (6 product lines)): Fixed 347.

Description:

PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.

cvelogic Threat Intelligence