Описание
The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex and Folsom, Django, and possibly other products allow remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) attack.
Отчет
This issue affects the versions of python as shipped with Red Hat Enterprise Linux 5, 6 and 7. Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | python | Will not fix | ||
| Red Hat Enterprise Linux 6 | python | Will not fix | ||
| Red Hat Enterprise Linux 7 | python | Will not fix | ||
| OpenStack Folsom for RHEL 6 | openstack-keystone | Fixed | RHSA-2013:0596 | 05.03.2013 |
| OpenStack Folsom for RHEL 6 | openstack-nova | Fixed | RHSA-2013:0657 | 21.03.2013 |
| OpenStack Folsom for RHEL 6 | openstack-cinder | Fixed | RHSA-2013:0658 | 21.03.2013 |
| OpenStack Folsom for RHEL 6 | Django14 | Fixed | RHSA-2013:0670 | 21.03.2013 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.8 Medium
CVSS2
Связанные уязвимости
The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex and Folsom, Django, and possibly other products allow remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) attack.
The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex and Folsom, Django, and possibly other products allow remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) attack.
The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used ...
EPSS
5.8 Medium
CVSS2