XML Entity Expansion in Linaro Automated Validation Architecture (LAVA) - CVE-2022-44641
Published: January 16, 2023
Vulnerability identifier: #VU71184
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-44641
CWE-ID: CWE-776
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to XML entity expansion when handling XMLRPC requests. A remote authenticated user can cause a recursive XML entity expansion and perform denial of service attack.
Affected software
Linaro Automated Validation Architecture (LAVA)
Debian Linux
lava (Debian package)
Debian Linux
lava (Debian package)
How to mitigate CVE-2022-44641
Install updates from vendor's website.
Linaro Automated Validation Architecture (LAVA) - update to 2022.11
lava (Debian package) - update to 2020.12-5+deb11u2
lava (Debian package) - update to 2020.12-5+deb11u2