CVE-2016-10149XML External Entity (XXE) Injection in Project Pysaml2

Severity
7.5HIGHNVD
EPSS
1.3%
top 20.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 24
Latest updateMay 29

Description

XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/python-pysaml2< python-pysaml2 3.0.0-5 (bookworm)

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

3
OSV
Pysaml2 does not sanitize XML responses2018-07-16
GHSA
Pysaml2 does not sanitize XML responses2018-07-16
OSV
CVE-2016-10149: XML External Entity (XXE) vulnerability in PySAML2 42017-03-24

📋Vendor Advisories

3
Ubuntu
PySAML2 vulnerability2017-08-24
Red Hat
python-pysaml2: Entity expansion issue2016-10-31
Debian
CVE-2016-10149: python-pysaml2 - XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remo...2016

💬Community

4
Bugzilla
CVE-2019-10149 exim: Remote command execution in deliver_message() function in /src/deliver.c2019-05-29
Bugzilla
CVE-2016-10149 python-pysaml2: various flaws [fedora-all]2017-01-23
Bugzilla
CVE-2016-10149 python-pysaml2: Entity expansion issue2017-01-23
Bugzilla
CVE-2016-10127 python-pysaml2: Vulnerable to XML external entity attack2017-01-10
CVE-2016-10149 — XML External Entity (XXE) Injection | cvebase