Authentication mechanism absence or evasion In pysaml2
Description
pysaml2 Improper Authentication vulnerability pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
pypi | 4.5.0 | ||
debian 11 | 4.5.0-2 | ||
debian 14 | 4.5.0-2 | ||
debian 12 | 4.5.0-2 | ||
debian 13 | 4.5.0-2 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10.
References
1. 2. 3. 4.