CVE-2013-2161
published 2013-08-20CVE-2013-2161: XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift responses…
PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.89%
77.3th percentile
XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift responses via an account name.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | swift | < swift 1.8.0-6 (bookworm) | swift 1.8.0-6 (bookworm) |
| openstack | swift | >= 0 < 1.8.0-6 | 1.8.0-6 |
| openstack | swift | >= 0 < 1.8.0-6 | 1.8.0-6 |
| openstack | swift | >= 0 < 1.8.0-6 | 1.8.0-6 |
| openstack | swift | >= 0 < 1.8.0-6 | 1.8.0-6 |
| openstack | swift | >= 0 < 1.9.0 | 1.9.0 |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_ubuntu9.8CRITICAL
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Swift Unchecked user input in XML responses
ghsa·2022-05-14
CVE-2013-2161 [HIGH] CWE-94 OpenStack Swift Unchecked user input in XML responses
OpenStack Swift Unchecked user input in XML responses
XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift responses via an account name.
OSV
OpenStack Swift Unchecked user input in XML responses
osv·2022-05-14
CVE-2013-2161 [HIGH] OpenStack Swift Unchecked user input in XML responses
OpenStack Swift Unchecked user input in XML responses
XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift responses via an account name.
OSV
CVE-2013-2161: XML injection vulnerability in account/utils
osv·2013-08-20·CVSS 7.5
CVE-2013-2161 [HIGH] CVE-2013-2161: XML injection vulnerability in account/utils
XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift responses via an account name.
Ubuntu
OpenStack Swift vulnerabilities
vendor_ubuntu·2013-06-20·CVSS 9.8
CVE-2012-4406 [CRITICAL] OpenStack Swift vulnerabilities
Title: OpenStack Swift vulnerabilities
Summary: Multiple security issues were fixed in OpenStack Swift.
Sebastian Krahmer discovered that Swift used the loads function in the
pickle Python module when it was configured to use memcached. A remote
attacker on the same network as memcached could exploit this to execute
arbitrary code. This update adds a new memcache_serialization_support
option to support secure json serialization. For details on this new
option, please see /usr/share/doc/swift-proxy/memcache.conf-sample. This
issue only affected Ubuntu 12.04 LTS. (CVE-2012-4406)
Alex Gaynor discovered that Swift did not safely generate XML. An
attacker could potentially craft an account name to generate arbitrary XML
responses to trigger vulnerabilties in software parsing Swift's XML.
(CV
Red Hat
Swift: Unchecked user input in Swift XML responses
vendor_redhat·2013-06-13·CVSS 7.5
CVE-2013-2161 [HIGH] Swift: Unchecked user input in Swift XML responses
Swift: Unchecked user input in Swift XML responses
XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift responses via an account name.
Statement: The Red Hat Security Response Team has rated this issue as having moderate security impact in OpenStack Essex (1.0) and Openstack Folsom (2.1). A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: gluster-swift (Red Hat Storage 2) - Affected
Debian
CVE-2013-2161: swift - XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizz...
vendor_debian·2013·CVSS 7.5
CVE-2013-2161 [HIGH] CVE-2013-2161: swift - XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizz...
XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift responses via an account name.
Scope: local
bookworm: resolved (fixed in 1.8.0-6)
bullseye: resolved (fixed in 1.8.0-6)
forky: resolved (fixed in 1.8.0-6)
sid: resolved (fixed in 1.8.0-6)
trixie: resolved (fixed in 1.8.0-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2161 OpenStack Swift: Unchecked user input in Swift XML responses [fedora-all]
bugzilla·2013-06-17·CVSS 7.5
CVE-2013-2161 [HIGH] CVE-2013-2161 OpenStack Swift: Unchecked user input in Swift XML responses [fedora-all]
CVE-2013-2161 OpenStack Swift: Unchecked user input in Swift XML responses [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this
Bugzilla
CVE-2013-2161 OpenStack Swift: Unchecked user input in Swift XML responses [epel-6]
bugzilla·2013-06-17·CVSS 7.5
CVE-2013-2161 [HIGH] CVE-2013-2161 OpenStack Swift: Unchecked user input in Swift XML responses [epel-6]
CVE-2013-2161 OpenStack Swift: Unchecked user input in Swift XML responses [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tracking
Bugzilla
CVE-2013-2161 OpenStack Swift: Unchecked user input in Swift XML responses
bugzilla·2013-06-11·CVSS 7.5
CVE-2013-2161 [HIGH] CVE-2013-2161 OpenStack Swift: Unchecked user input in Swift XML responses
CVE-2013-2161 OpenStack Swift: Unchecked user input in Swift XML responses
Alex Gaynor from Rackspace reported a vulnerability in XML handling
within Swift account servers. Account strings were unescaped in xml
listings, and an attacker could potentially generate unparsable or
arbitrary XML responses which may be used to leverage other
vulnerabilities in the calling software.
Discussion:
Created attachment 759406
Patch
---
Proposed public disclosure date/time:
Thursday, June 13, 2013, 1500UTC
Please do not make the issue public (or release public patches)
before this coordinated embargo date.
---
Statement:
The Red Hat Security Response Team has rated this issue as having moderate security impact in OpenStack Essex (1.0) and Openstack Folsom (2.1). A future update may address this
http://lists.opensuse.org/opensuse-updates/2013-07/msg00021.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0993.htmlhttp://www.debian.org/security/2012/dsa-2737http://www.openwall.com/lists/oss-security/2013/06/13/4https://bugs.launchpad.net/swift/+bug/1183884http://lists.opensuse.org/opensuse-updates/2013-07/msg00021.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0993.htmlhttp://www.debian.org/security/2012/dsa-2737http://www.openwall.com/lists/oss-security/2013/06/13/4https://bugs.launchpad.net/swift/+bug/1183884
2013-08-20
Published