-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| ipsilon | pip | >= 0.1.0, < 1.0.1 | 1.2.0 |
The vulnerability stems from improper permission checks in the SAML2 SP update logic. The commit diff shows a fix in providers/saml2/admin.py where the permission check for the SP owner was corrected. The original code checked the wrong field, allowing any authenticated user to alter the SP name, leading to duplicate entries and DoS. The file path and commit message explicitly identify the flawed permission-checking logic in the SP update function as the root cause.
Ongoing coverage of React2Shell