PT-2013-4887 · Openstack · Havana+1

·

CVE-2013-4179

·

Published

2013-09-16

·

Updated

2026-07-06

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions OpenStack Compute (Nova) versions 2013.1.3 and earlier, Havana versions before havana-3
Description The issue allows remote attackers to cause a denial of service, resulting in resource consumption and crash, via an XML Entity Expansion (XEE) attack. This is due to an incomplete fix for a previous issue.
Recommendations For OpenStack Compute (Nova) versions 2013.1.3 and earlier, update to a version that includes the complete fix for the issue. For Havana versions before havana-3, update to havana-3 or later to resolve the issue.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-4179
GHSA-J6XH-Q826-55JW
PYSEC-2026-875
RHSA-2013:1199

Affected Products

Havana
Openstack Compute