Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j6xh-q826-55jw

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

OpenStack Compute (Nova) vulnerable to denial of service via XML Entity Expansion attack

The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana-3, and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.

Пакеты

Наименование

nova

pip
Затронутые версииВерсия исправления

<= 2013.1.3

2013.2

EPSS

Процентиль: 71%
0.00669
Низкий

Дефекты

CWE-119

Связанные уязвимости

ubuntu
больше 12 лет назад

The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana-3, and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.

redhat
больше 12 лет назад

The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana-3, and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.

nvd
больше 12 лет назад

The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana-3, and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.

debian
больше 12 лет назад

The security group extension in OpenStack Compute (Nova) Grizzly 2013. ...

EPSS

Процентиль: 71%
0.00669
Низкий

Дефекты

CWE-119