CVE-2017-1000433
published 2018-01-02CVE-2017-1000433: pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing…
PriorityP341high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
2.52%
83.2th percentile
pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | python-pysaml2 | < python-pysaml2 4.5.0-2 (bookworm) | python-pysaml2 4.5.0-2 (bookworm) |
| pysaml2_project | pysaml2 | <= 4.4.0 | — |
| pysaml2_project | pysaml2 | >= 0 < 4.5.0 | 4.5.0 |
| vllm | vllm | >= 0 < 0.22.0 | 0.22.0 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution
ghsa·2026-06-16
CVE-2026-41523 [HIGH] CWE-617 vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution
vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution
### Summary
An `assert`-based security check in vLLM's activation function loading allows any unauthenticated attacker to achieve arbitrary code execution on the server by publishing a malicious HuggingFace model, when vLLM runs in Python optimized mode (`python -O` or `PYTHONOPTIMIZE=1`).
### Details
vLLM uses an `assert` statement at [`vllm/model_executor/layers/pooler/activations.py:48`](https://github.com/vllm-project/vllm/blob/main/vllm/model_executor/layers/pooler/activations.py#L48) as its sole security control to restrict which activation functions can be loaded from a HuggingFace model's `config.json`:
```python
# vllm/model_executor/layers/pooler/activations.py:35-
OSV
pysaml2 Improper Authentication vulnerability
osv·2018-07-13
CVE-2017-1000433 [CRITICAL] pysaml2 Improper Authentication vulnerability
pysaml2 Improper Authentication vulnerability
pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.
GHSA
pysaml2 Improper Authentication vulnerability
ghsa·2018-07-13
CVE-2017-1000433 [CRITICAL] CWE-287 pysaml2 Improper Authentication vulnerability
pysaml2 Improper Authentication vulnerability
pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.
OSV
CVE-2017-1000433: pysaml2 version 4
osv·2018-01-02·CVSS 8.1
CVE-2017-1000433 [HIGH] CVE-2017-1000433: pysaml2 version 4
pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.
Ubuntu
PySAML2 vulnerability
vendor_ubuntu·2018-01-08
CVE-2017-1000433 PySAML2 vulnerability
Title: PySAML2 vulnerability
Summary: PySAML2 could allow authentication without a password.
It was discovered that PySAML2 incorrectly accepted any password when run
with python optimizations enabled. An attacker could use this issue to
authenticate as any user without a valid password.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python-pysaml2: Access restriction bypass
vendor_redhat·2017-09-10·CVSS 8.1
CVE-2017-1000433 [HIGH] CWE-287 python-pysaml2: Access restriction bypass
python-pysaml2: Access restriction bypass
pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.
Statement: Red Hat Product Security has rated this issue as having security impact of Low for:
* Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7
* Red Hat OpenStack Platform 8.0 (Liberty)
* Red Hat OpenStack Platform 9.0 (Mitaka)
* Red Hat OpenStack Platform 10.0 (Newton)
* Red Hat OpenStack Platform 11.0 (Ocata)
* Red Hat OpenStack Platform 12.0 (Pike)
Although the affected code is present in shipped packages, python-pysaml2 is included only as a dependency of other packages. The affected code cannot be reached in any supported configuration of Red Hat OpenSt
Debian
CVE-2017-1000433: python-pysaml2 - pysaml2 version 4.4.0 and older accept any password when run with python optimiz...
vendor_debian·2017·CVSS 8.1
CVE-2017-1000433 [HIGH] CVE-2017-1000433: python-pysaml2 - pysaml2 version 4.4.0 and older accept any password when run with python optimiz...
pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.
Scope: local
bookworm: resolved (fixed in 4.5.0-2)
bullseye: resolved (fixed in 4.5.0-2)
forky: resolved (fixed in 4.5.0-2)
sid: resolved (fixed in 4.5.0-2)
trixie: resolved (fixed in 4.5.0-2)
No detection rules found.
No public exploits indexed.
https://github.com/rohe/pysaml2/issues/451https://lists.debian.org/debian-lts-announce/2018/07/msg00000.htmlhttps://lists.debian.org/debian-lts-announce/2021/02/msg00038.htmlhttps://security.gentoo.org/glsa/201801-11https://github.com/rohe/pysaml2/issues/451https://lists.debian.org/debian-lts-announce/2018/07/msg00000.htmlhttps://lists.debian.org/debian-lts-announce/2021/02/msg00038.htmlhttps://security.gentoo.org/glsa/201801-11
2018-01-02
Published