CVE-2013-4202: XEE
The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volumetransfer.py) APIs in OpenStack Cinder Grizzly 2013.1.3 and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4202?
CVE-2013-4202 has a high severity rating due to its potential for causing denial of service.
How do I fix CVE-2013-4202?
To fix CVE-2013-4202, upgrade OpenStack Cinder to version 7.0.0a0 or later.
What systems are affected by CVE-2013-4202?
CVE-2013-4202 affects OpenStack Cinder versions prior to 2013.1.4, including 2013.1.3 and earlier.
What type of attack does CVE-2013-4202 enable?
CVE-2013-4202 enables a denial of service attack through XML Entity Expansion (XEE).
Is CVE-2013-4202 applicable to Ubuntu systems?
Yes, CVE-2013-4202 is applicable to Ubuntu systems running version 13.04 with affected OpenStack Cinder installations.