VDB
CVE-2013-2161
CVE-2013-2161
PUBLISHED
CVSS 7.5 HIGH
XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift responses via an account name.
EPSS 1.89% · 78.0th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
1.89%
78.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| openstack | grizzly | |
| openstack | havana | |
| n/a | n/a | n/a |
| opensuse | opensuse | 12.3 |
| openstack | folsom | |
| PyPI | swift | 0 |
Timeline
- Aug 20, 2013 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- openSUSE-SU-2013:1146 vendor-advisory
- DSA-2737 vendor-advisory
- https://bugs.launchpad.net/swift/+bug/1183884 url
- RHSA-2013:0993 vendor-advisory
- [oss-security] 20130613 [OSSA 2013-016] Unchecked user input in Swift XML responses (CVE-2013-2161) mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2013-2161 advisory
- https://github.com/openstack/swift/commit/6659382c4fa348e1ebbce2424968dd7267ea1db1 url
- https://github.com/openstack/swift/commit/8f9b135e0a16478a628f20224ce5babe62d4aaba url
- https://github.com/openstack/swift package
- http://github.com/openstack/swift/commit/4eed6bf5b5028409f730be97ddcfb6bfa893c976 url
- http://github.com/openstack/swift/commit/92d7eadd328797d392758c79e258c8455874c80e url