PT-2013-3571 · Openstack · Openstack Swift
Alex Gaynor
·
Publicado
2013-08-20
·
Atualizado
2022-05-14
·
CVE-2013-2161
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OpenStack Swift versions Folsom through Havana
Description
The issue allows attackers to trigger invalid or spoofed responses via an account name, potentially exploiting an XML injection vulnerability in the account/utils.py file.
Recommendations
For OpenStack Swift versions Folsom through Havana, update to a version that includes a fix for this issue to prevent XML injection attacks.
Correção
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Openstack Swift