Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-44641


In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can submit crafted XMLRPC requests that cause a recursive XML entity expansion, leading to excessive use of memory on the server and a Denial of Service.


Published

2022-11-18T21:15:11.787

Last Modified

2025-04-29T19:15:52.773

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-776
  • Type: Secondary
    CWE-776

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application linaro lava < 2022.11 Yes
Operating System debian debian_linux 10.0 Yes
Operating System debian debian_linux 11.0 Yes

References