CVE-2013-1664

medium
Published 2013-04-03 · Modified 2024-12-06
CVSS v3
CVSS v2
5.0
VIR risk
5.0

Description

XML Entity Expansion (XEE) in Django

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-1664

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://lists.openstack.org/pipermail/openstack-announce/2013-February/000078.html

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2012.2.3-1
debian debianbullseyefixed2012.2.3-1
debian debianforkyfixed2012.2.3-1
debian debiansidfixed2012.2.3-1
debian debiantrixiefixed2012.2.3-1

Package impact

EcosystemPackageVulnerableFixed
python PyPIdjango>=1.3.0,<1.3.61.3.6
python PyPIdjango>=1.4.0,<1.4.41.4.4

Application impact

VendorProductVersionsFixed
openstackcinder_folsom-
openstackcompute_\(nova\)_essex-
openstackcompute_\(nova\)_folsom-
openstackfolsom-
openstackgrizzly-
openstackkeystone_essex-

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.