CVE-2013-1665

medium
Published 2013-04-03 · Modified 2024-12-06
CVSS v3
CVSS v2
5.0
VIR risk
5.0

Description

XML External Entity (XXE) in Django

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-1665

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://bugs.launchpad.net/keystone/+bug/1100279

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://lists.openstack.org/pipermail/openstack-announce/2013-February/000078.html

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2012.1.1-13
debian debianbullseyefixed2012.1.1-13
debian debianforkyfixed2012.1.1-13
debian debiansidfixed2012.1.1-13
debian debiantrixiefixed2012.1.1-13

Package impact

EcosystemPackageVulnerableFixed
python PyPIdjango>=1.3.0,<1.3.61.3.6
python PyPIdjango>=1.4.0,<1.4.41.4.4

Application impact

VendorProductVersionsFixed
openstackfolsom-
openstackkeystone_essex-

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.