Publish GHSA-924m-4pmx-c67h

This commit is contained in:
advisory-database[bot]
2023-03-31 14:52:30 +00:00
parent facb8ae613
commit 09a4b1b8be
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-924m-4pmx-c67h",
"modified": "2021-09-07T20:34:38Z",
"modified": "2023-03-31T14:51:18Z",
"published": "2018-07-13T16:01:17Z",
"aliases": [
"CVE-2017-1000433"
],
"summary": "High severity vulnerability that affects pysaml2",
"summary": "pysaml2 Improper Authentication vulnerability",
"details": "pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.",
"severity": [
{
@@ -45,8 +45,12 @@
"url": "https://github.com/rohe/pysaml2/issues/451"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-924m-4pmx-c67h"
"type": "WEB",
"url": "https://github.com/IdentityPython/pysaml2/pull/454"
},
{
"type": "WEB",
"url": "https://github.com/IdentityPython/pysaml2/commit/6312a41e037954850867f29d329e5007df1424a5"
},
{
"type": "PACKAGE",