CVE-2013-2161

OpenStack Swift Folsom, Grizzly, Havana - XML Injection via Account Name

Title source: llm
STIX 2.1

Description

XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift responses via an account name.

References (5)

Core 5
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2012/dsa-2737
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2013-07/msg00021.html
Issue Tracking x_refsource_confirm
https://bugs.launchpad.net/swift/+bug/1183884
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-0993.html
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/06/13/4

Scores

EPSS 0.0033
EPSS Percentile 56.0%

Details

CWE
CWE-94
Status published
Products (5)
openstack/folsom
openstack/grizzly
openstack/havana
opensuse/opensuse 12.3
pypi/swift 0 - 1.9.0PyPI
Published Aug 20, 2013
Tracked Since Feb 18, 2026