CVE-2022-44641: Medium severity Linaro LAVA vulnerability
In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can submit crafted XMLRPC requests that cause a recursive XML entity expansion, leading to excessive use of memory on the server and a Denial of Service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/lavato a version that resolves this vulnerability.Fixed in 2019.01-5+deb10u2Fixed in 2020.12-5+deb11u2Fixed in 2023.01-2
Event History
Frequently Asked Questions
What is CVE-2022-44641?
CVE-2022-44641 is a vulnerability in Linaro Automated Validation Architecture (LAVA) that allows users with valid credentials to submit crafted XMLRPC requests, causing a Denial of Service.
How does CVE-2022-44641 affect Linaro LAVA?
CVE-2022-44641 affects Linaro LAVA versions before 2022.11, where users with valid credentials can exploit it.
What is the severity level of CVE-2022-44641?
The severity level of CVE-2022-44641 is high, with a CVSS score of 6.5.
What are the affected versions of Linaro LAVA?
Linaro LAVA versions before 2022.11 are affected by CVE-2022-44641.
How can I mitigate CVE-2022-44641?
To mitigate CVE-2022-44641, users are advised to upgrade to Linaro LAVA version 2022.11 or later.