The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade novaUpgrade cinderUpgrade keystone | Jul 30, 2024 | Apr 3, 2013 |
| Freebsd | — | Upgrade py26-djangoUpgrade py27-django | Dec 10, 2025 | Feb 24, 2013 |
| Gentoo Linux | — | Upgrade dev-libs/libxml2.Upgrade app-emulation/emul-linux-x86-baselibs. | Oct 30, 2017 | Apr 2, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 19, 2013 |
| Suse | — | Upgrade openstack-quickstartUpgrade openstack-cinder-volumeUpgrade openstack-glance-docUpgrade openstack-nova-novncproxyUpgrade openstack-nova-objectstoreUpgrade openstack-nova-computeUpgrade openstack-nova-apiUpgrade python-glanceUpgrade openstack-novaUpgrade openstack-swift-testUpgrade python-keystoneclient-testUpgrade python-keystoneclientUpgrade python-keystoneclient-docUpgrade openstack-nova-networkUpgrade openstack-quantum-docUpgrade openstack-cinder-schedulerUpgrade openstack-nova-docUpgrade openstack-cinderUpgrade openstack-nova-certUpgrade openstack-glanceUpgrade python-cinderclient-testUpgrade python-cinderclient-docUpgrade openstack-quantumUpgrade openstack-keystone-docUpgrade openstack-dashboardUpgrade python-cinderUpgrade openstack-keystone-testUpgrade python-quantumUpgrade openstack-dashboard-testUpgrade openstack-nova-vncproxyUpgrade openstack-nova-volumeUpgrade openstack-swiftUpgrade openstack-swift-proxyUpgrade python-cinderclientUpgrade openstack-nova-testUpgrade python-keystoneUpgrade openstack-swift-containerUpgrade openstack-cinder-apiUpgrade python-novaUpgrade openstack-swift-docUpgrade openstack-cinder-docUpgrade openstack-glance-testUpgrade openstack-quantum-testUpgrade python-swiftUpgrade openstack-nova-schedulerUpgrade openstack-keystoneUpgrade openstack-cinder-testUpgrade python-horizonUpgrade openstack-swift-accountUpgrade openstack-swift-objectUpgrade python-django_openstack_auth | Dec 12, 2013 | Apr 2, 2013 |
| Ubuntu | — | Upgrade python-djangoUpgrade python-keystoneUpgrade python-novaUpgrade python-cinder | Nov 8, 2024 | Apr 3, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub