Safety vulnerability ID: 35437
The information on this page was manually curated by our Cybersecurity Intelligence Team.
The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana-3, and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.
Latest version: 30.0.0
Cloud computing fabric controller
The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana-3, and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.
CONFIRM:https://bugs.launchpad.net/ossa/+bug/1190229: https://bugs.launchpad.net/ossa/+bug/1190229
REDHAT:RHSA-2013:1199: http://rhn.redhat.com/errata/RHSA-2013-1199.html
UBUNTU:USN-2005-1: http://www.ubuntu.com/usn/USN-2005-1
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application