CVE-2013-1665
published 2013-04-03CVE-2013-1665: The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex and Folsom, Django, and possibly other products allow remote…
PriorityP433medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
4.59%
90.6th percentile
The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex and Folsom, Django, and possibly other products allow remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) attack.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | keystone | < keystone 2012.1.1-13 (bookworm) | keystone 2012.1.1-13 (bookworm) |
| debian | python-django | < keystone 2012.1.1-13 (bookworm) | keystone 2012.1.1-13 (bookworm) |
| djangoproject | django | >= 1.3.0 < 1.3.6 | 1.3.6 |
| djangoproject | django | >= 1.4.0 < 1.4.4 | 1.4.4 |
| openstack | keystone | >= 0 < 2012.1.1-13 | 2012.1.1-13 |
| openstack | keystone | >= 0 < 2012.1.1-13 | 2012.1.1-13 |
| openstack | keystone | >= 0 < 2012.1.1-13 | 2012.1.1-13 |
| openstack | keystone | >= 0 < 2012.1.1-13 | 2012.1.1-13 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_ubuntu6.4MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Django vulnerabilities
vendor_ubuntu·2013-03-07·CVSS 6.4
CVE-2012-4520 [MEDIUM] Django vulnerabilities
Title: Django vulnerabilities
Summary: Several security issues were fixed in Django.
James Kettle discovered that Django did not properly filter the Host HTTP
header when processing certain requests. An attacker could exploit this to
generate and display arbitrary URLs to users. Although this issue had been
previously addressed in USN-1632-1, this update adds additional hardening
measures to host header validation. This update also adds a new
ALLOWED_HOSTS setting that can be set to a list of acceptable values for
headers. (CVE-2012-4520)
Orange Tsai discovered that Django incorrectly performed permission checks
when displaying the history view in the admin interface. An administrator
could use this flaw to view the history of any object, regardless of
intended permissions. (CVE-2013-03
Ubuntu
OpenStack Keystone vulnerabilities
vendor_ubuntu·2013-02-20·CVSS 5.0
CVE-2013-0282 [MEDIUM] OpenStack Keystone vulnerabilities
Title: OpenStack Keystone vulnerabilities
Summary: Keystone could be made to crash or expose sensitive information over the
network.
Nathanael Burton discovered that Keystone did not properly verify disabled
users. An authenticated but disabled user would continue to have access
rights that were removed. (CVE-2013-0282)
Jonathan Murray discovered that Keystone would allow XML entity processing.
A remote unauthenticated attacker could exploit this to cause a denial of
service via resource exhaustion. Authenticated users could also use this to
view arbitrary files on the Keystone server. (CVE-2013-1664, CVE-2013-1665)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bindings: External entity expansion in Python XML libraries inflicts potential security flaws and DoS vulnerabilities
vendor_redhat·2013-02-19·CVSS 5.0
CVE-2013-1665 [MEDIUM] bindings: External entity expansion in Python XML libraries inflicts potential security flaws and DoS vulnerabilities
bindings: External entity expansion in Python XML libraries inflicts potential security flaws and DoS vulnerabilities
The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex and Folsom, Django, and possibly other products allow remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) attack.
Statement: This issue affects the versions of python as shipped with Red Hat Enterprise Linux 5, 6 and 7. Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates.
Package: python (Red Hat Enterprise Linux 5) - Will not fix
Package: python (Red Hat Enterprise Linux 6)
Debian
CVE-2013-1665: keystone - The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenSt...
vendor_debian·2013·CVSS 5.0
CVE-2013-1665 [MEDIUM] CVE-2013-1665: keystone - The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenSt...
The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex and Folsom, Django, and possibly other products allow remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) attack.
Scope: local
bookworm: resolved (fixed in 2012.1.1-13)
bullseye: resolved (fixed in 2012.1.1-13)
forky: resolved (fixed in 2012.1.1-13)
sid: resolved (fixed in 2012.1.1-13)
trixie: resolved (fixed in 2012.1.1-13)
OSV
XML External Entity (XXE) in Django
osv·2022-05-17
CVE-2013-1665 [MEDIUM] XML External Entity (XXE) in Django
XML External Entity (XXE) in Django
The XML libraries for Python as used in OpenStack Keystone Essex and Folsom, Django, and possibly other products allow remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) attack.
GHSA
XML External Entity (XXE) in Django
ghsa·2022-05-17
CVE-2013-1665 [MEDIUM] CWE-200 XML External Entity (XXE) in Django
XML External Entity (XXE) in Django
The XML libraries for Python as used in OpenStack Keystone Essex and Folsom, Django, and possibly other products allow remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) attack.
OSV
CVE-2013-1665: The XML libraries for Python 3
osv·2013-04-03·CVSS 5.0
CVE-2013-1665 [MEDIUM] CVE-2013-1665: The XML libraries for Python 3
The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex and Folsom, Django, and possibly other products allow remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) attack.
No detection rules found.
Bugzilla
Django: XML entity attacks
bugzilla·2013-02-20·CVSS 5.0
[MEDIUM] Django: XML entity attacks
Django: XML entity attacks
James Bennett of Django reports:
Django's serialization framework includes support for serializing to, and deserializing from, XML. Django's XML deserialization is vulnerable to entity-expansion and external-entity/DTD attacks.
To remedy this, Django's XML deserializer no longer allows DTDs, performs entity expansion, or fetches external entities/DTDs. Note that this only protects Django's XML serialization framework; if your application parses XML, we recommend you look into the defusedxml Python packages which remedy this for Python itself.
Because this issue also affects Python's XML libraries, it is covered by Python's CVE-2013-1664 and CVE-2013-1665.
External reference:
https://www.djangoproject.com/weblog/2013/feb/19/security/
Discussion:
Created Dja
Bugzilla
CVE-2013-1665 Python xml bindings: External entity expansion in Python XML libraries inflicts potential security flaws and DoS vulnerabilities
bugzilla·2013-02-20·CVSS 5.0
CVE-2013-1665 [MEDIUM] CVE-2013-1665 Python xml bindings: External entity expansion in Python XML libraries inflicts potential security flaws and DoS vulnerabilities
CVE-2013-1665 Python xml bindings: External entity expansion in Python XML libraries inflicts potential security flaws and DoS vulnerabilities
Christian Heimes reports:
Entity declarations can contain more than just text for replacement. They can
also point to external resources by public identifiers or system identifiers.
System identifiers are standard URIs. When the URI is a URL (e.g. a http://
locator) some parsers download the resource from the remote location and embed
them into the XML document verbatim.
Using External entity expansion opens the door to plenty of exploits. An attacker can abuse a vulnerable XML library and application to rebound and forward network
requests with the IP address of the server. It highly depends on the parser and
the application what kind of exploit
Bugzilla
CVE-2013-1664 CVE-2013-1665 libxml2: DoS (excessive CPU consumption) by performing string substitutions during entities expansion [fedora-all]
bugzilla·2013-02-20·CVSS 5.0
CVE-2013-1664 [MEDIUM] CVE-2013-1664 CVE-2013-1665 libxml2: DoS (excessive CPU consumption) by performing string substitutions during entities expansion [fedora-all]
CVE-2013-1664 CVE-2013-1665 libxml2: DoS (excessive CPU consumption) by performing string substitutions during entities expansion [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and t
Bugzilla
CVE-2013-1664 CVE-2013-1665 libxml2: DoS (excessive CPU consumption) by performing string substitutions during entities expansion [fedora-all]
bugzilla·2013-02-20·CVSS 5.0
CVE-2013-1664 [MEDIUM] CVE-2013-1664 CVE-2013-1665 libxml2: DoS (excessive CPU consumption) by performing string substitutions during entities expansion [fedora-all]
CVE-2013-1664 CVE-2013-1665 libxml2: DoS (excessive CPU consumption) by performing string substitutions during entities expansion [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and t
Bugzilla
CVE-2013-1664 CVE-2013-1665 OpenStack keystone: XML entity parsing
bugzilla·2013-02-12·CVSS 5.0
CVE-2013-1664 [MEDIUM] CVE-2013-1664 CVE-2013-1665 OpenStack keystone: XML entity parsing
CVE-2013-1664 CVE-2013-1665 OpenStack keystone: XML entity parsing
Thierry Carrez ([email protected]) reports:
Title: Information leak and Denial of Service using XML entities
Reporter: Jonathan Murray (NCC Group), Joshua Harlow (Yahoo!), Stuart Stent
Products: Keystone, Nova, Cinder
Affects: All versions
Description:
Jonathan Murray from NCC Group, Joshua Harlow from Yahoo! and Stuart
Stent independently reported a vulnerability in the parsing of XML
requests in Keystone, Nova and Cinder. By using entities in XML
requests, an unauthenticated attacker may consume excessive resources on
the Keystone, Nova or Cinder API servers, resulting in a denial of
service and potentially a crash. Authenticated attackers may also
leverage XML entities to read the content of a local file on the
Ke
Bugzilla
CVE-2013-1664 CVE-2013-1665 OpenStack nova: XML entity parsing
bugzilla·2013-02-12·CVSS 5.0
CVE-2013-1664 [MEDIUM] CVE-2013-1664 CVE-2013-1665 OpenStack nova: XML entity parsing
CVE-2013-1664 CVE-2013-1665 OpenStack nova: XML entity parsing
Thierry Carrez ([email protected]) reports:
Title: Information leak and Denial of Service using XML entities
Reporter: Jonathan Murray (NCC Group), Joshua Harlow (Yahoo!), Stuart Stent
Products: Keystone, Nova, Cinder
Affects: All versions
Description:
Jonathan Murray from NCC Group, Joshua Harlow from Yahoo! and Stuart
Stent independently reported a vulnerability in the parsing of XML
requests in Keystone, Nova and Cinder. By using entities in XML
requests, an unauthenticated attacker may consume excessive resources on
the Keystone, Nova or Cinder API servers, resulting in a denial of
service and potentially a crash. This only affects servers with XML
support enabled.
Proposed patches:
See attached patches for current
Bugzilla
CVE-2013-1664 CVE-2013-1665 OpenStack cinder: XML entity parsing
bugzilla·2013-02-12·CVSS 5.0
CVE-2013-1664 [MEDIUM] CVE-2013-1664 CVE-2013-1665 OpenStack cinder: XML entity parsing
CVE-2013-1664 CVE-2013-1665 OpenStack cinder: XML entity parsing
Thierry Carrez ([email protected]) reports:
Title: Information leak and Denial of Service using XML entities
Reporter: Jonathan Murray (NCC Group), Joshua Harlow (Yahoo!), Stuart Stent
Products: Keystone, Nova, Cinder
Affects: All versions
Description:
Jonathan Murray from NCC Group, Joshua Harlow from Yahoo! and Stuart
Stent independently reported a vulnerability in the parsing of XML
requests in Keystone, Nova and Cinder. By using entities in XML
requests, an unauthenticated attacker may consume excessive resources on
the Keystone, Nova or Cinder API servers, resulting in a denial of
service and potentially a crash. This only affects servers with XML
support enabled.
Proposed patches:
See attached patches for curren
http://blog.python.org/2013/02/announcing-defusedxml-fixes-for-xml.htmlhttp://bugs.python.org/issue17239http://lists.openstack.org/pipermail/openstack-announce/2013-February/000078.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0657.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0658.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0670.htmlhttp://ubuntu.com/usn/usn-1757-1http://www.debian.org/security/2013/dsa-2634http://www.openwall.com/lists/oss-security/2013/02/19/2http://www.openwall.com/lists/oss-security/2013/02/19/4https://bugs.launchpad.net/keystone/+bug/1100279http://blog.python.org/2013/02/announcing-defusedxml-fixes-for-xml.htmlhttp://bugs.python.org/issue17239http://lists.openstack.org/pipermail/openstack-announce/2013-February/000078.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0657.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0658.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0670.htmlhttp://ubuntu.com/usn/usn-1757-1http://www.debian.org/security/2013/dsa-2634http://www.openwall.com/lists/oss-security/2013/02/19/2http://www.openwall.com/lists/oss-security/2013/02/19/4https://bugs.launchpad.net/keystone/+bug/1100279
2013-04-03
Published