CVE-2017-11427 describes a critical vulnerability in OneLogin PythonSAML 2.3.0 and earlier, where improper handling of XML DOM traversal and canonicalization allows attackers to manipulate SAML data without invalidating cryptographic signatures. This flaw, rated 9.8 CVSS (Critical), enables potential authentication bypass to SAML service providers, leading to high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation is confirmed, the vulnerability has garnered significant community attention and media coverage, indicating its potential for abuse.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.3.0CPE matchmatch criteria | cpe:2.3:a:onelogin:pythonsaml:*:*:*:*:*:*:*:* | ||
< 2.3.0CPE match | cpe:2.3:a:onelogin:pythonsaml:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.