CVE-2013-2161

XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift responses via an account name.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openstack:folsom:-:*:*:*:*:*:*:*
cpe:2.3:a:openstack:grizzly:-:*:*:*:*:*:*:*
cpe:2.3:a:openstack:havana:-:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*

History

21 Nov 2024, 01:51

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-updates/2013-07/msg00021.html - () http://lists.opensuse.org/opensuse-updates/2013-07/msg00021.html -
References () http://rhn.redhat.com/errata/RHSA-2013-0993.html - () http://rhn.redhat.com/errata/RHSA-2013-0993.html -
References () http://www.debian.org/security/2012/dsa-2737 - () http://www.debian.org/security/2012/dsa-2737 -
References () http://www.openwall.com/lists/oss-security/2013/06/13/4 - () http://www.openwall.com/lists/oss-security/2013/06/13/4 -
References () https://bugs.launchpad.net/swift/+bug/1183884 - () https://bugs.launchpad.net/swift/+bug/1183884 -

Information

Published : 2013-08-20 22:55

Updated : 2024-11-21 01:51


NVD link : CVE-2013-2161

Mitre link : CVE-2013-2161

CVE.ORG link : CVE-2013-2161


JSON object : View

Products Affected

openstack

  • grizzly
  • havana
  • folsom

opensuse

  • opensuse
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')