cbcvebase.
CVE-2013-4202
published 2013-09-16

CVE-2013-4202: The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenStack Cinder Grizzly 2013.1.3 and earlier allows…

PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
2.60%
83.7th percentile
The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenStack Cinder Grizzly 2013.1.3 and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.

Affected

8 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debiancinder< cinder 2013.1.2-4 (bookworm)cinder 2013.1.2-4 (bookworm)
openstackcinder>= 0 < 2013.1.2-42013.1.2-4
openstackcinder>= 0 < 2013.1.2-42013.1.2-4
openstackcinder>= 0 < 2013.1.2-42013.1.2-4
openstackcinder>= 0 < 2013.1.2-42013.1.2-4
openstackcinder>= 0 < 7.0.0a07.0.0a0
openstackcinder2013.1 – 2013.1.3

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
ghsa5.0MEDIUM
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.