id: PYSEC-2019-198 details: OneLogin PythonSAML 2.3.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers. affected: - package: name: python-saml ecosystem: PyPI purl: pkg:pypi/python-saml ranges: - type: ECOSYSTEM events: - introduced: '0' - fixed: 2.4.0 versions: - 2.0.0 - 2.0.1 - 2.0.2 - 2.1.0 - 2.1.1 - 2.1.2 - 2.1.3 - 2.1.4 - 2.1.5 - 2.1.6 - 2.1.7 - 2.1.8 - 2.1.9 - 2.2.0 - 2.2.1 - 2.2.2 - 2.2.3 - 2.3.0 references: - type: WEB url: https://www.kb.cert.org/vuls/id/475445 - type: ARTICLE url: https://duo.com/blog/duo-finds-saml-vulnerabilities-affecting-multiple-implementations - type: ADVISORY url: https://github.com/advisories/GHSA-j8j8-348v-wfm3 aliases: - CVE-2017-11427 - GHSA-j8j8-348v-wfm3 modified: '2021-08-27T03:22:18.581552Z' published: '2019-04-17T14:29:00Z'