CVE-2013-4202
16.09.2013, 19:14
The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenStack Cinder Grizzly 2013.1.3 and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.Enginsight
Vendor | Product | Version |
---|---|---|
openstack | cinder | 2013.1 ≤ 𝑥 ≤ 2013.1.3 |
canonical | ubuntu_linux | 13.04 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration