CVE-2013-1665Sensitive Information Exposure in Django

Severity
5.0MEDIUMNVD
EPSS
3.0%
top 13.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 3
Latest updateMay 17

Description

The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex and Folsom, Django, and possibly other products allow remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) attack.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debianopenstack/keystone< 2012.1.1-13+3
PyPIdjangoproject/django1.3.01.3.6+1

Patches

🔴Vulnerability Details

4
OSV
XML External Entity (XXE) in Django2022-05-17
GHSA
XML External Entity (XXE) in Django2022-05-17
CVEList
CVE-2013-1665: The XML libraries for Python 32013-04-03
OSV
CVE-2013-1665: The XML libraries for Python 32013-04-03

💥Exploits & PoCs

1
Exploit-DB
ownCloud 6.0.0a - Multiple Vulnerabilities2014-02-05

📋Vendor Advisories

4
Ubuntu
Django vulnerabilities2013-03-07
Ubuntu
OpenStack Keystone vulnerabilities2013-02-20
Red Hat
bindings: External entity expansion in Python XML libraries inflicts potential security flaws and DoS vulnerabilities2013-02-19
Debian
CVE-2013-1665: keystone - The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenSt...2013

💬Community

7
Bugzilla
CVE-2013-1665 Python xml bindings: External entity expansion in Python XML libraries inflicts potential security flaws and DoS vulnerabilities2013-02-20
Bugzilla
CVE-2013-1664 CVE-2013-1665 libxml2: DoS (excessive CPU consumption) by performing string substitutions during entities expansion [fedora-all]2013-02-20
Bugzilla
CVE-2013-1664 CVE-2013-1665 libxml2: DoS (excessive CPU consumption) by performing string substitutions during entities expansion [fedora-all]2013-02-20
Bugzilla
Django: XML entity attacks2013-02-20
Bugzilla
CVE-2013-1664 CVE-2013-1665 OpenStack keystone: XML entity parsing2013-02-12
CVE-2013-1665 — Sensitive Information Exposure | cvebase