Skip to content

XML External Entity (XXE) Vulnerability for v7.5.4 #1020

Description

@GanNicholas

Hi i am using pysaml2 library in my code and it is getting flagged for XML External Entity (XXE)

The full vulnerability explanation as below:
The pysaml2 package is vulnerable to an XML External Entity (XXE) attack. The package uses defusedxml to process the uploaded XML document without properly validating the document type definition (DTD) attribute values as forbid_dtd is not enabled by default.

NOTE: This vulnerability has been assigned CVE-2017-1000061.

May I know if there is a fix in place for this? Thank you.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions