cbcvebase.
CVE-2013-1664
published 2013-04-03

CVE-2013-1664: The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom…

PriorityP425medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
4.86%
91.1th percentile
The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debiancinder< cinder 2013.1.2-4 (bookworm)cinder 2013.1.2-4 (bookworm)
debiancinder< cinder 2012.2.3-1 (bookworm)cinder 2012.2.3-1 (bookworm)
debiankeystone< cinder 2012.2.3-1 (bookworm)cinder 2012.2.3-1 (bookworm)
debiannova< nova 2013.1.3-1 (bookworm)nova 2013.1.3-1 (bookworm)
debiannova< cinder 2012.2.3-1 (bookworm)cinder 2012.2.3-1 (bookworm)
djangoprojectdjango>= 1.3.0 < 1.3.61.3.6
djangoprojectdjango>= 1.4.0 < 1.4.41.4.4
openstackcinder>= 0 < 2012.2.3-12012.2.3-1
openstackcinder>= 0 < 2013.1.2-42013.1.2-4
openstackcinder>= 0 < 2012.2.3-12012.2.3-1
openstackcinder>= 0 < 2013.1.2-42013.1.2-4
openstackcinder>= 0 < 2012.2.3-12012.2.3-1
openstackcinder>= 0 < 2013.1.2-42013.1.2-4
openstackcinder>= 0 < 2012.2.3-12012.2.3-1
openstackcinder>= 0 < 2013.1.2-42013.1.2-4
openstackcinder>= 0 < 7.0.0a07.0.0a0
openstackcinder2013.1 – 2013.1.3
openstackcompute
openstackhavana<= havana-2
openstackhavana
openstackkeystone>= 0 < 2012.1.1-132012.1.1-13
openstackkeystone>= 0 < 2012.1.1-132012.1.1-13
openstackkeystone>= 0 < 2012.1.1-132012.1.1-13
openstackkeystone>= 0 < 2012.1.1-132012.1.1-13

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa5.0MEDIUM
osv5.0MEDIUM
vendor_ubuntu6.4MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.