CVE-2013-1664

The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
VendorProductVersion
openstackcinder_folsom
-
openstackcompute_\(nova\)_essex
-
openstackcompute_\(nova\)_folsom
-
openstackfolsom
-
openstackgrizzly
-
openstackkeystone_essex
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
cinder
bullseye
2:17.0.1-1+deb11u1
fixed
bullseye (security)
2:17.4.0-1~deb11u2
fixed
bookworm
2:21.3.1-1~deb12u1
fixed
bookworm (security)
2:21.3.1-1~deb12u1
fixed
sid
2:25.0.0-1
fixed
keystone
bullseye
2:18.0.0-3+deb11u1
fixed
bookworm
2:22.0.0-2
fixed
sid
2:26.0.0-1
fixed
trixie
2:26.0.0-1
fixed
nova
bullseye
2:22.0.1-2+deb11u1
fixed
bullseye (security)
2:22.4.0-1~deb11u5
fixed
bookworm
2:26.2.2-1~deb12u3
fixed
bookworm (security)
2:26.2.2-1~deb12u3
fixed
sid
2:30.0.0-1
fixed
trixie
2:30.0.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cinder
quantal
Fixed 2012.2.1-0ubuntu1.1
released
precise
dne
oneiric
dne
lucid
dne
hardy
dne
keystone
quantal
Fixed 2012.2.1-0ubuntu1.2
released
precise
Fixed 2012.1+stable~20120824-a16a0ab9-0ubuntu2.5
released
oneiric
ignored
lucid
dne
hardy
dne
nova
quantal
Fixed 2012.2.1+stable-20121212-a99a802e-0ubuntu1.2
released
precise
Fixed 2012.1.3+stable-20120827-4d2a4afe-0ubuntu1.2
released
oneiric
Fixed 2011.3-0ubuntu6.12
released
lucid
dne
hardy
dne
python-django
quantal
Fixed 1.4.1-2ubuntu0.3
released
precise
Fixed 1.3.1-4ubuntu1.6
released
oneiric
Fixed 1.3-2ubuntu1.6
released
lucid
Fixed 1.1.1-2ubuntu1.8
released
hardy
ignored
quantum
quantal
not-affected
precise
not-affected
oneiric
dne
lucid
dne
hardy
dne