SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-1000433

This allows attackers to log in as any user without knowing their password.

HIGH 8.1EPSS 2.54%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.54%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.

CVSS 3.1
8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
2.54% probability · 84th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
pysaml2 project/pysaml2 · debian/debian linux
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.