CVE-2017-1000433: Debian Linux
High severity, CVSS 8.1. EPSS: 2.5% chance of exploitation in the next 30 days.
pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.
Affected products
- Debian Debian Linux: version 8.0 only; version 9.0 only
- PYSAML2 Project PYSAML2: up to and including 4.4.0
Published 2018-01-02. Last modified 2026-06-17.