PT-2022-27274 · Linaro · Lava

Igor Ponomarev

·

Published

2022-11-18

·

Updated

2023-02-01

·

CVE-2022-44641

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linaro Automated Validation Architecture (LAVA) versions prior to 2022.11
Description The issue allows users with valid credentials to submit crafted XMLRPC requests, causing a recursive XML entity expansion. This leads to excessive use of memory on the server and results in a Denial of Service.
Recommendations For versions prior to 2022.11, update to version 2022.11 or later to resolve the issue. As a temporary workaround, consider restricting access to XMLRPC requests until a patch is applied.

Fix

DoS

XML Entity Expansion

Weakness Enumeration

Related Identifiers

CVE-2022-44641
DLA-3276-1
DSA-5318-1

Affected Products

Lava