XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.
| Software | From | Fixed in |
|---|---|---|
| pysaml2_project / pysaml2 | - | 4.4.0.x |
| debian / debian_linux | 8.0 | 8.0.x |
pysaml2
|
- | 4.5.0 |