xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade expatUpgrade xmlrpc-c-develUpgrade mingw64-expatUpgrade xmlrpc-c-c++Upgrade thunderbirdUpgrade expat-develUpgrade mingw32-expatUpgrade firefoxUpgrade xmlrpc-c-client++ | May 4, 2022 | Feb 16, 2022 |
| Alpine Linux | — | Upgrade expat | Aug 22, 2024 | Feb 16, 2022 |
| Amazon Linux Ami 2 | — | Upgrade xmlrpc-c-client++Upgrade xmlrpc-cUpgrade xmlrpc-c-develUpgrade thunderbird-debuginfoUpgrade xmlrpc-c-c++Upgrade xmlrpc-c-debuginfoUpgrade expat-develUpgrade xmlrpc-c-appsUpgrade expat-debuginfoUpgrade thunderbirdUpgrade expat-staticUpgrade expat | Jul 4, 2022 | Feb 16, 2022 |
| Amazon_linux | — | Upgrade xmlrpc-cUpgrade expat | Mar 11, 2022 | Feb 16, 2022 |
| Amazon_linux_2023 | — | Upgrade xmlrpc-c-client++Upgrade xmlrpc-c-c++-debuginfoUpgrade xmlrpc-c-clientUpgrade xmlrpc-c-debuginfoUpgrade xmlrpc-c-apps-debuginfoUpgrade expat-develUpgrade xmlrpc-c-c++Upgrade xmlrpc-c-appsUpgrade xmlrpc-cUpgrade expatUpgrade expat-staticUpgrade expat-debuginfoUpgrade expat-debugsourceUpgrade xmlrpc-c-client++-debuginfoUpgrade xmlrpc-c-client-debuginfo | Feb 17, 2025 | Feb 19, 2022 |
| Aruba Aos 10 | — | - AirWave Management Platform
- 8.2.14.1 and above
- Aruba Analytics and Location Engine
- 2.2.0.3 and above
Release ETA - late July 2022
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.2.1 and above
- Aruba Central On-Premises
-2.5.5.0 and above
Release ETA - late July 2022
- Aruba ClearPass Policy Manager
- 6.10.5 and above
- 6.9.11 and above
- 6.8.9 with Hotfix for Q1 2022 Security issues applied
- ArubaOS-CX Switches
- 10.10.0002 and above
- 10.09.1031 and above
- 10.08.1070 and above
- 10.07.0080 and above
- 10.06.0210 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- Please note that this only affected controllers and
gateways based on the x86 architecture
This includes the following models
- Aruba 9000 Series Controllers
- Aruba 9200 Series Controllers
- Aruba Virtual Mobility Controllers
- Aruba Virtual and Hardware-based Mobility Conductors
-The fixed code versions are as follows
- ArubaOS 8.6.x: 8.6.0.19 and above
Release ETA - early September 2022
- ArubaOS 8.7.x: 8.7.1.10 and above
Release ETA - late July 2022
- ArubaOS 8.10.x: 8.10.0.3 and above
Release ETA - late August 2022
- ArubaOS 10.3.x: 10.3.1.1 and above
Release ETA - early August 2022
- SDWAN 2.X: 8.7.0.0-2.3.0.8 and above
Release ETA - late July 2022
- Aruba EdgeConnect Enterprise
- ECOS 9.1.1.4 and above
- ECOS 9.0.7.0 and above
- ECOS 8.3.7.0 and above
- Impact of this vulnerability on ECOS is very low.
Fixes will be applied only to the ECOS versions
that are listed above due to the minimal risk involved.
- Aruba EdgeConnect Enterprise Orchestrator (on-premises)
- Orchestrator does not use expat library. However:
- Customers using CentOS are suggested to run 'yum
update expat' from the administrative command line to
address this vulnerability; to verify if the patch has been
applied, run 'rpm -q --changelog expat' and look for
the specific CVEs. If the output shows 'Resolves', the
patches for the CVE(s) have already been applied.
- OR -
- Upgrading (from 9.0.6 or later) to any newer Orchestrator
version automatically updates expat and resolves this
vulnerability.
- New virtual machine images already have the fix for this
vulnerability.
- Customers using Fedora must upgrade to CentOS for support
of security updates. Please contact Customer Support for
the procedure.
- Aruba Virtual Intranet Access (VIA)
- Affects macOS/OSX versions only. Others are unaffected
- 4.4.0 and above
Aruba does not evaluate or patch product versions that have
reached their End of Support (EoS) milestone. For more
information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Jan 14, 2025 | May 17, 2022 |
| Aruba Aos 8 | — | - AirWave Management Platform
- 8.2.14.1 and above
- Aruba Analytics and Location Engine
- 2.2.0.3 and above
Release ETA - late July 2022
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.2.1 and above
- Aruba Central On-Premises
-2.5.5.0 and above
Release ETA - late July 2022
- Aruba ClearPass Policy Manager
- 6.10.5 and above
- 6.9.11 and above
- 6.8.9 with Hotfix for Q1 2022 Security issues applied
- ArubaOS-CX Switches
- 10.10.0002 and above
- 10.09.1031 and above
- 10.08.1070 and above
- 10.07.0080 and above
- 10.06.0210 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- Please note that this only affected controllers and
gateways based on the x86 architecture
This includes the following models
- Aruba 9000 Series Controllers
- Aruba 9200 Series Controllers
- Aruba Virtual Mobility Controllers
- Aruba Virtual and Hardware-based Mobility Conductors
-The fixed code versions are as follows
- ArubaOS 8.6.x: 8.6.0.19 and above
Release ETA - early September 2022
- ArubaOS 8.7.x: 8.7.1.10 and above
Release ETA - late July 2022
- ArubaOS 8.10.x: 8.10.0.3 and above
Release ETA - late August 2022
- ArubaOS 10.3.x: 10.3.1.1 and above
Release ETA - early August 2022
- SDWAN 2.X: 8.7.0.0-2.3.0.8 and above
Release ETA - late July 2022
- Aruba EdgeConnect Enterprise
- ECOS 9.1.1.4 and above
- ECOS 9.0.7.0 and above
- ECOS 8.3.7.0 and above
- Impact of this vulnerability on ECOS is very low.
Fixes will be applied only to the ECOS versions
that are listed above due to the minimal risk involved.
- Aruba EdgeConnect Enterprise Orchestrator (on-premises)
- Orchestrator does not use expat library. However:
- Customers using CentOS are suggested to run 'yum
update expat' from the administrative command line to
address this vulnerability; to verify if the patch has been
applied, run 'rpm -q --changelog expat' and look for
the specific CVEs. If the output shows 'Resolves', the
patches for the CVE(s) have already been applied.
- OR -
- Upgrading (from 9.0.6 or later) to any newer Orchestrator
version automatically updates expat and resolves this
vulnerability.
- New virtual machine images already have the fix for this
vulnerability.
- Customers using Fedora must upgrade to CentOS for support
of security updates. Please contact Customer Support for
the procedure.
- Aruba Virtual Intranet Access (VIA)
- Affects macOS/OSX versions only. Others are unaffected
- 4.4.0 and above
Aruba does not evaluate or patch product versions that have
reached their End of Support (EoS) milestone. For more
information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Jan 14, 2025 | May 17, 2022 |
| Aruba Aos Cx | — | - AirWave Management Platform
- 8.2.14.1 and above
- Aruba Analytics and Location Engine
- 2.2.0.3 and above
Release ETA - late July 2022
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.2.1 and above
- Aruba Central On-Premises
-2.5.5.0 and above
Release ETA - late July 2022
- Aruba ClearPass Policy Manager
- 6.10.5 and above
- 6.9.11 and above
- 6.8.9 with Hotfix for Q1 2022 Security issues applied
- ArubaOS-CX Switches
- 10.10.0002 and above
- 10.09.1031 and above
- 10.08.1070 and above
- 10.07.0080 and above
- 10.06.0210 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- Please note that this only affected controllers and
gateways based on the x86 architecture
This includes the following models
- Aruba 9000 Series Controllers
- Aruba 9200 Series Controllers
- Aruba Virtual Mobility Controllers
- Aruba Virtual and Hardware-based Mobility Conductors
-The fixed code versions are as follows
- ArubaOS 8.6.x: 8.6.0.19 and above
Release ETA - early September 2022
- ArubaOS 8.7.x: 8.7.1.10 and above
Release ETA - late July 2022
- ArubaOS 8.10.x: 8.10.0.3 and above
Release ETA - late August 2022
- ArubaOS 10.3.x: 10.3.1.1 and above
Release ETA - early August 2022
- SDWAN 2.X: 8.7.0.0-2.3.0.8 and above
Release ETA - late July 2022
- Aruba EdgeConnect Enterprise
- ECOS 9.1.1.4 and above
- ECOS 9.0.7.0 and above
- ECOS 8.3.7.0 and above
- Impact of this vulnerability on ECOS is very low.
Fixes will be applied only to the ECOS versions
that are listed above due to the minimal risk involved.
- Aruba EdgeConnect Enterprise Orchestrator (on-premises)
- Orchestrator does not use expat library. However:
- Customers using CentOS are suggested to run 'yum
update expat' from the administrative command line to
address this vulnerability; to verify if the patch has been
applied, run 'rpm -q --changelog expat' and look for
the specific CVEs. If the output shows 'Resolves', the
patches for the CVE(s) have already been applied.
- OR -
- Upgrading (from 9.0.6 or later) to any newer Orchestrator
version automatically updates expat and resolves this
vulnerability.
- New virtual machine images already have the fix for this
vulnerability.
- Customers using Fedora must upgrade to CentOS for support
of security updates. Please contact Customer Support for
the procedure.
- Aruba Virtual Intranet Access (VIA)
- Affects macOS/OSX versions only. Others are unaffected
- 4.4.0 and above
Aruba does not evaluate or patch product versions that have
reached their End of Support (EoS) milestone. For more
information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Feb 24, 2025 | May 17, 2022 |
| Centos_linux | — | Upgrade thunderbirdUpgrade expat-debugsourceUpgrade expatUpgrade firefoxUpgrade xmlrpc-c-debugsourceUpgrade expat-staticUpgrade expat-develUpgrade thunderbird-debuginfoUpgrade xmlrpc-c-debuginfoUpgrade xmlrpc-c-client-debuginfoUpgrade firefox-debugsourceUpgrade thunderbird-debugsourceUpgrade xmlrpc-cUpgrade expat-debuginfoUpgrade xmlrpc-c-c++-debuginfoUpgrade xmlrpc-c-apps-debuginfoUpgrade firefox-debuginfoUpgrade xmlrpc-c-client | Mar 11, 2022 | Feb 16, 2022 |
| Debian | — | Upgrade expat | Feb 24, 2022 | Feb 16, 2022 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Apr 30, 2022 |
| Gentoo Linux | — | Upgrade dev-libs/expat. | Sep 30, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp10 | — | Upgrade expat | Jun 7, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp3 | — | Upgrade expatUpgrade expat-devel | May 25, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp5 | — | Upgrade expat-staticUpgrade expat-develUpgrade expat | Apr 26, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp8 | — | Upgrade expatUpgrade expat-devel | Apr 26, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp9 | — | Upgrade expat | Jun 16, 2022 | Feb 16, 2022 |
| Ibm Aix | — | Apply the fix or workaround for python_advisory | Oct 12, 2022 | Feb 16, 2022 |
| Ibm Http_server | — | Apply IBM HTTP Server version 7.0.0.46 or laterApply IBM HTTP Server version 8.0.0.16 or laterApply IBM HTTP Server version 8.5.5.22 or laterApply IBM HTTP Server version 9.0.5.12 or laterApply IBM HTTP Server Interim Fix PH44271 | Aug 31, 2022 | Mar 15, 2022 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Sep 4, 2023 |
| Oracle_linux | — | Upgrade expatUpgrade xmlrpc-cUpgrade firefoxUpgrade thunderbirdUpgrade expat-develUpgrade xmlrpc-c-clientUpgrade expat-staticUpgrade xmlrpc-c-client++Upgrade xmlrpc-c-c++ | Mar 11, 2022 | Feb 19, 2022 |
| Redhat_linux | — | Upgrade expat-staticUpgrade expat-debuginfoUpgrade xmlrpc-c-client++Upgrade xmlrpc-c-c++-debuginfoUpgrade expat-develUpgrade xmlrpc-c-debuginfoUpgrade expatUpgrade xmlrpc-c-c++Upgrade xmlrpc-c-apps-debuginfoUpgrade firefox-debugsourceUpgrade mingw64-expatUpgrade mingw64-expat-debuginfoUpgrade mingw32-expat-debuginfoUpgrade xmlrpc-c-develUpgrade xmlrpc-c-client-debuginfoUpgrade thunderbird-debugsourceNo solution existsUpgrade expat-debugsourceUpgrade firefox-debuginfoUpgrade mingw32-expatUpgrade xmlrpc-cUpgrade thunderbird-debuginfoUpgrade thunderbirdUpgrade xmlrpc-c-debugsourceUpgrade firefox | Mar 11, 2022 | Feb 16, 2022 |
| Rocky_linux | — | Upgrade xmlrpc-c-develUpgrade firefox-debuginfoUpgrade xmlrpc-cUpgrade expat-debugsourceUpgrade thunderbird-debuginfoUpgrade thunderbird-debugsourceUpgrade thunderbirdUpgrade expat-develUpgrade firefoxUpgrade xmlrpc-c-c++Upgrade xmlrpc-c-client-debuginfoUpgrade expatUpgrade xmlrpc-c-debuginfoUpgrade firefox-debugsourceUpgrade xmlrpc-c-client++-debuginfoUpgrade xmlrpc-c-c++-debuginfoUpgrade xmlrpc-c-clientUpgrade xmlrpc-c-client++Upgrade xmlrpc-c-debugsourceUpgrade expat-debuginfo | Mar 5, 2024 | Feb 16, 2022 |
| Suse | — | Upgrade libexpat-develUpgrade libexpat-devel-32bitUpgrade libexpat1Upgrade libexpat1-32bitUpgrade expat | Mar 4, 2022 | Feb 16, 2022 |
| Ubuntu | — | Upgrade libxmlrpc-c++8v5 (Ubuntu Pro)Upgrade libxmlrpc-core-c3t64 (Ubuntu Pro)Upgrade libcoin80v5 (Ubuntu Pro)Upgrade ayttm (Ubuntu Pro)Upgrade lib64expat1 (Ubuntu Pro)Upgrade swish-e (Ubuntu Pro)Upgrade libinsighttoolkit3.20 (Ubuntu Pro)Upgrade libexpat1 (Ubuntu Pro)Upgrade libxmlrpc-core-c3 (Ubuntu Pro)Upgrade cableswig (Ubuntu Pro)Upgrade xmlrpc-api-utils (Ubuntu Pro)Upgrade libcoin80-runtime (Ubuntu Pro)Upgrade libxmlrpc-c++8t64 (Ubuntu Pro)Upgrade libxmltok1 (Ubuntu Pro)Upgrade libxmlrpc-c++8 (Ubuntu Pro)Upgrade libcoin80 (Ubuntu Pro)Upgrade libexpat1 | Feb 22, 2022 | Feb 16, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 16, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub