CVE-2017-11427: Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversal
OneLogin PythonSAML 2.3.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11427?
CVE-2017-11427 has been classified as a high severity vulnerability due to its potential to allow attackers to manipulate SAML data.
How do I fix CVE-2017-11427?
To remediate CVE-2017-11427, upgrade PythonSAML to version 2.4.0 or later.
What versions of PythonSAML are affected by CVE-2017-11427?
CVE-2017-11427 affects PythonSAML version 2.3.0 and earlier.
What can an attacker achieve by exploiting CVE-2017-11427?
An attacker exploiting CVE-2017-11427 may manipulate SAML data without invalidating the cryptographic signature, potentially bypassing security measures.
Who is impacted by CVE-2017-11427?
Organizations using OneLogin PythonSAML versions 2.3.0 and earlier are impacted by CVE-2017-11427.