VDB
KO
MEDIUM

GHSA-qrh7-x6fp-c2mp

XML Entity Expansion (XEE) in Django

Details

The XML libraries for Python, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / django
Introduced in: 1.3.0 Fixed in: 1.3.6
Fix pip install --upgrade 'django>=1.3.6'
PyPI / django
Introduced in: 1.4.0 Fixed in: 1.4.4
Fix pip install --upgrade 'django>=1.4.4'

References