The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex and Folsom, Django, and possibly other products allow remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) attack.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade python-djangoUpgrade keystone | Jul 30, 2024 | Apr 3, 2013 |
| Freebsd | — | Upgrade py26-djangoUpgrade py27-django | Dec 10, 2025 | Feb 24, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 19, 2013 |
| Suse | — | Upgrade openstack-keystone-docUpgrade openstack-nova-computeUpgrade python-djangoUpgrade openstack-cinder-schedulerUpgrade openstack-nova-networkUpgrade python-keystoneclient-docUpgrade python-cinderclient-docUpgrade openstack-cinder-volumeUpgrade openstack-glance-docUpgrade python-cinderclient-testUpgrade openstack-nova-apiUpgrade openstack-cinderUpgrade python-keystoneclient-testUpgrade python-glanceUpgrade openstack-novaUpgrade openstack-nova-objectstoreUpgrade openstack-nova-docUpgrade openstack-nova-novncproxyUpgrade openstack-swift-testUpgrade openstack-glanceUpgrade openstack-nova-certUpgrade python-keystoneclientUpgrade openstack-quantumUpgrade openstack-glance-testUpgrade openstack-swift-objectUpgrade openstack-swift-docUpgrade openstack-cinder-testUpgrade openstack-nova-schedulerUpgrade openstack-nova-volumeUpgrade python-novaUpgrade openstack-swift-proxyUpgrade openstack-swiftUpgrade python-django_openstack_authUpgrade openstack-dashboard-testUpgrade openstack-keystone-testUpgrade openstack-cinder-apiUpgrade python-horizonUpgrade python-cinderUpgrade openstack-swift-containerUpgrade python-swiftUpgrade openstack-keystoneUpgrade openstack-cinder-docUpgrade openstack-nova-testUpgrade openstack-quickstartUpgrade openstack-quantum-docUpgrade openstack-quantum-testUpgrade openstack-nova-vncproxyUpgrade openstack-swift-accountUpgrade python-keystoneUpgrade python-cinderclientUpgrade python-quantumUpgrade openstack-dashboard | Dec 12, 2013 | Apr 2, 2013 |
| Ubuntu | — | Upgrade python-keystoneUpgrade python-django | Nov 8, 2024 | Apr 3, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub