The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex and Folsom, Django, and possibly other products allow remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) attack.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade keystoneUpgrade python-django | Jul 30, 2024 | Apr 3, 2013 |
| Freebsd | — | Upgrade py27-djangoUpgrade py26-django | Dec 10, 2025 | Feb 24, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 19, 2013 |
| Suse | — | Upgrade openstack-nova-certUpgrade openstack-cinderUpgrade python-cinderclient-docUpgrade openstack-nova-objectstoreUpgrade python-djangoUpgrade python-glanceUpgrade openstack-nova-networkUpgrade openstack-glanceUpgrade openstack-nova-docUpgrade openstack-quantumUpgrade openstack-glance-docUpgrade openstack-novaUpgrade openstack-swift-testUpgrade python-keystoneclient-testUpgrade openstack-keystone-docUpgrade python-cinderclient-testUpgrade openstack-cinder-volumeUpgrade openstack-nova-novncproxyUpgrade python-keystoneclient-docUpgrade openstack-nova-apiUpgrade openstack-nova-computeUpgrade python-keystoneclientUpgrade openstack-cinder-schedulerUpgrade openstack-swiftUpgrade python-cinderUpgrade openstack-quantum-testUpgrade python-horizonUpgrade openstack-quantum-docUpgrade openstack-keystone-testUpgrade openstack-cinder-apiUpgrade openstack-swift-accountUpgrade python-cinderclientUpgrade openstack-dashboardUpgrade python-novaUpgrade openstack-nova-testUpgrade openstack-cinder-docUpgrade openstack-quickstartUpgrade openstack-dashboard-testUpgrade openstack-nova-vncproxyUpgrade python-swiftUpgrade openstack-swift-proxyUpgrade openstack-cinder-testUpgrade openstack-swift-containerUpgrade python-django_openstack_authUpgrade openstack-glance-testUpgrade openstack-swift-objectUpgrade openstack-nova-volumeUpgrade openstack-swift-docUpgrade python-keystoneUpgrade openstack-nova-schedulerUpgrade python-quantumUpgrade openstack-keystone | Dec 12, 2013 | Apr 2, 2013 |
| Ubuntu | — | Upgrade python-keystoneUpgrade python-django | Nov 8, 2024 | Apr 3, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub