CVE-2013-2161: Code Injection
Published Aug 20, 2013
·Updated
XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift responses via an account name.
Affected Software
5 affected componentsFixes available
pip/swift<1.9.0
1.9.0
Openstack folsom
Openstack Grizzly
Openstack Havana
openSUSE openSUSE=12.3
Event History
Aug 20, 2013
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·02:10 AM
Frequently Asked Questions
1
What is the severity of CVE-2013-2161?
CVE-2013-2161 is classified as a moderate severity vulnerability due to the potential for XML injection in OpenStack Swift.
2
How do I fix CVE-2013-2161?
To fix CVE-2013-2161, upgrade to version 1.9.0 or later of the Swift package.
3
Which versions of OpenStack are affected by CVE-2013-2161?
CVE-2013-2161 affects OpenStack Swift versions in Folsom, Grizzly, and Havana releases.
4
What type of vulnerability is CVE-2013-2161?
CVE-2013-2161 is an XML injection vulnerability that allows attackers to manipulate Swift responses.
5
Can CVE-2013-2161 impact application security?
Yes, CVE-2013-2161 can impact application security by allowing spoofed account response manipulations.