Back to Database
Status published
Critical
CVE-2016-10127
PySAML2 allows remote attackers to conduct XML external entity (XXE)...
Vulnerability Description
PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-10127
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/rohe/pysaml2/issues/366
- https://github.com/rohe/pysaml2/pull/379
- http://www.openwall.com/lists/oss-security/2017/01/19/5
- https://github.com/rohe/pysaml2/commit/6e09a25d9b4b7aa7a506853210a9a14100b8bc9b
- http://www.securityfocus.com/bid/95376
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850716
More from pysaml2 project
View All →CVE-2020-5390
PySAML2 before 5.0.0 does not check that the signature in...
High
7.5
CVE-2017-1000433
pysaml2 version 4.4.0 and older accept any password when run...
High
8.1
CVE-2017-1000246
Python package pysaml2 version 4.4.0 and earlier reuses the initialization...
Medium
5.3
CVE-2016-10149
XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier...
High
7.5
Affected Vendor
pysaml2 project
View all reports →Affected Software
pysaml2
Vulnerable Versions:
Unknown
Timeline
Official Publish:
March 3rd, 2017
Last Modified:
August 6th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.