{"id":"CVE-2013-2161","aliases":["GHSA-9xgv-6v35-mmcj","PYSEC-2026-930"],"title":"OpenStack Swift Unchecked user input in XML responses","summary":"OpenStack Swift Unchecked user input in XML responses","severity":"high","vendor":"swift","product":"swift","ecosystem":"pip","affected":["swift < 1.9.0"],"patched":["swift 1.9.0"],"published":"2022-05-14","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-9xgv-6v35-mmcj","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-2161"},{"url":"https://github.com/openstack/swift/commit/6659382c4fa348e1ebbce2424968dd7267ea1db1"},{"url":"https://github.com/openstack/swift/commit/8f9b135e0a16478a628f20224ce5babe62d4aaba"},{"url":"https://bugs.launchpad.net/swift/+bug/1183884"},{"url":"https://github.com/openstack/swift"},{"url":"http://github.com/openstack/swift/commit/4eed6bf5b5028409f730be97ddcfb6bfa893c976"},{"url":"http://github.com/openstack/swift/commit/92d7eadd328797d392758c79e258c8455874c80e"},{"url":"http://lists.opensuse.org/opensuse-updates/2013-07/msg00021.html"},{"url":"http://rhn.redhat.com/errata/RHSA-2013-0993.html"},{"url":"http://www.debian.org/security/2012/dsa-2737"},{"url":"http://www.openwall.com/lists/oss-security/2013/06/13/4"}],"tags":["osv","pip"],"epss":0.0191,"epssPercentile":0.78608,"ingestedAt":"2026-07-08T18:25:48.118Z","slug":"CVE-2013-2161","body":"## Overview\n\nXML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift responses via an account name.\n\n## Affected packages\n\n- `swift < 1.9.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `swift 1.9.0`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}