The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.
2013-04-03T00:55:02.177
2025-04-11T00:51:21.963
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | openstack | cinder_folsom | - | Yes |
| Application | openstack | compute_\(nova\)_essex | - | Yes |
| Application | openstack | compute_\(nova\)_folsom | - | Yes |
| Application | openstack | folsom | - | Yes |
| Application | openstack | grizzly | - | Yes |
| Application | openstack | keystone_essex | - | Yes |