From 09a4b1b8be529bf66a3a87100f0b3703a7830ba8 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 31 Mar 2023 14:52:30 +0000 Subject: [PATCH] Publish GHSA-924m-4pmx-c67h --- .../07/GHSA-924m-4pmx-c67h/GHSA-924m-4pmx-c67h.json | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/advisories/github-reviewed/2018/07/GHSA-924m-4pmx-c67h/GHSA-924m-4pmx-c67h.json b/advisories/github-reviewed/2018/07/GHSA-924m-4pmx-c67h/GHSA-924m-4pmx-c67h.json index 1cf18e76927..fbcc7a85d6c 100644 --- a/advisories/github-reviewed/2018/07/GHSA-924m-4pmx-c67h/GHSA-924m-4pmx-c67h.json +++ b/advisories/github-reviewed/2018/07/GHSA-924m-4pmx-c67h/GHSA-924m-4pmx-c67h.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-924m-4pmx-c67h", - "modified": "2021-09-07T20:34:38Z", + "modified": "2023-03-31T14:51:18Z", "published": "2018-07-13T16:01:17Z", "aliases": [ "CVE-2017-1000433" ], - "summary": "High severity vulnerability that affects pysaml2", + "summary": "pysaml2 Improper Authentication vulnerability", "details": "pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.", "severity": [ { @@ -45,8 +45,12 @@ "url": "https://github.com/rohe/pysaml2/issues/451" }, { - "type": "ADVISORY", - "url": "https://github.com/advisories/GHSA-924m-4pmx-c67h" + "type": "WEB", + "url": "https://github.com/IdentityPython/pysaml2/pull/454" + }, + { + "type": "WEB", + "url": "https://github.com/IdentityPython/pysaml2/commit/6312a41e037954850867f29d329e5007df1424a5" }, { "type": "PACKAGE",