Description
The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5025 | The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. |
Github GHSA |
GHSA-qrh7-x6fp-c2mp | XML Entity Expansion (XEE) in Django |
Ubuntu USN |
USN-1730-1 | OpenStack Keystone vulnerabilities |
Ubuntu USN |
USN-1731-1 | OpenStack Cinder vulnerability |
Ubuntu USN |
USN-1734-1 | OpenStack Nova vulnerability |
Ubuntu USN |
USN-1757-1 | Django vulnerabilities |
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T15:13:32.247Z
Reserved: 2013-02-13T00:00:00.000Z
Link: CVE-2013-1664
No data.
Status : Deferred
Published: 2013-04-03T00:55:02.177
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-1664
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA
Ubuntu USN