Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-1665

Опубликовано: 19 фев. 2013
Источник: redhat
CVSS2: 5.8
EPSS Низкий

Описание

The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex and Folsom, Django, and possibly other products allow remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) attack.

Отчет

This issue affects the versions of python as shipped with Red Hat Enterprise Linux 5, 6 and 7. Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5pythonWill not fix
Red Hat Enterprise Linux 6pythonWill not fix
Red Hat Enterprise Linux 7pythonWill not fix
OpenStack Folsom for RHEL 6openstack-keystoneFixedRHSA-2013:059605.03.2013
OpenStack Folsom for RHEL 6openstack-novaFixedRHSA-2013:065721.03.2013
OpenStack Folsom for RHEL 6openstack-cinderFixedRHSA-2013:065821.03.2013
OpenStack Folsom for RHEL 6Django14FixedRHSA-2013:067021.03.2013

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=912982bindings: External entity expansion in Python XML libraries inflicts potential security flaws and DoS vulnerabilities

EPSS

Процентиль: 91%
0.04631
Низкий

5.8 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 13 лет назад

The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex and Folsom, Django, and possibly other products allow remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) attack.

nvd
больше 13 лет назад

The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex and Folsom, Django, and possibly other products allow remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) attack.

debian
больше 13 лет назад

The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used ...

github
больше 4 лет назад

XML External Entity (XXE) in Django

EPSS

Процентиль: 91%
0.04631
Низкий

5.8 Medium

CVSS2