Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-4202

Опубликовано: 16 сент. 2013
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenStack Cinder Grizzly 2013.1.3 and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:openstack:cinder:*:*:*:*:*:*:*:*
Версия от 2013.1 (включая) до 2013.1.3 (включая)
Конфигурация 2
cpe:2.3:o:canonical:ubuntu_linux:13.04:*:*:*:*:*:*:*

EPSS

Процентиль: 74%
0.00841
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-399

Связанные уязвимости

ubuntu
больше 12 лет назад

The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenStack Cinder Grizzly 2013.1.3 and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.

redhat
больше 12 лет назад

The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenStack Cinder Grizzly 2013.1.3 and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.

debian
больше 12 лет назад

The (1) backup (api/contrib/backups.py) and (2) volume transfer (contr ...

github
больше 3 лет назад

OpenStack Cinder Denial of Service using XML entities

EPSS

Процентиль: 74%
0.00841
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-399