xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade firefoxUpgrade expat-develUpgrade mingw32-expatUpgrade thunderbirdUpgrade xmlrpc-c-client++Upgrade expatUpgrade xmlrpc-c-c++Upgrade mingw64-expatUpgrade xmlrpc-c-devel | May 4, 2022 | Feb 16, 2022 |
| Alpine Linux | — | Upgrade expat | Aug 22, 2024 | Feb 16, 2022 |
| Amazon Linux Ami 2 | — | Upgrade thunderbirdUpgrade expat-staticUpgrade expat-debuginfoUpgrade expatUpgrade xmlrpc-c-appsUpgrade thunderbird-debuginfoUpgrade xmlrpc-c-develUpgrade xmlrpc-c-debuginfoUpgrade xmlrpc-c-client++Upgrade xmlrpc-cUpgrade expat-develUpgrade xmlrpc-c-c++ | Jul 4, 2022 | Feb 16, 2022 |
| Amazon_linux | — | Upgrade expatUpgrade xmlrpc-c | Mar 11, 2022 | Feb 16, 2022 |
| Amazon_linux_2023 | — | Upgrade xmlrpc-c-apps-debuginfoUpgrade xmlrpc-c-c++Upgrade xmlrpc-c-clientUpgrade xmlrpc-c-debuginfoUpgrade xmlrpc-c-client++Upgrade xmlrpc-c-c++-debuginfoUpgrade xmlrpc-c-appsUpgrade expat-develUpgrade expat-staticUpgrade xmlrpc-c-client++-debuginfoUpgrade xmlrpc-c-client-debuginfoUpgrade expat-debuginfoUpgrade expat-debugsourceUpgrade expatUpgrade xmlrpc-c | Feb 17, 2025 | Feb 19, 2022 |
| Aruba Aos 10 | — | - AirWave Management Platform
- 8.2.14.1 and above
- Aruba Analytics and Location Engine
- 2.2.0.3 and above
Release ETA - late July 2022
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.2.1 and above
- Aruba Central On-Premises
-2.5.5.0 and above
Release ETA - late July 2022
- Aruba ClearPass Policy Manager
- 6.10.5 and above
- 6.9.11 and above
- 6.8.9 with Hotfix for Q1 2022 Security issues applied
- ArubaOS-CX Switches
- 10.10.0002 and above
- 10.09.1031 and above
- 10.08.1070 and above
- 10.07.0080 and above
- 10.06.0210 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- Please note that this only affected controllers and
gateways based on the x86 architecture
This includes the following models
- Aruba 9000 Series Controllers
- Aruba 9200 Series Controllers
- Aruba Virtual Mobility Controllers
- Aruba Virtual and Hardware-based Mobility Conductors
-The fixed code versions are as follows
- ArubaOS 8.6.x: 8.6.0.19 and above
Release ETA - early September 2022
- ArubaOS 8.7.x: 8.7.1.10 and above
Release ETA - late July 2022
- ArubaOS 8.10.x: 8.10.0.3 and above
Release ETA - late August 2022
- ArubaOS 10.3.x: 10.3.1.1 and above
Release ETA - early August 2022
- SDWAN 2.X: 8.7.0.0-2.3.0.8 and above
Release ETA - late July 2022
- Aruba EdgeConnect Enterprise
- ECOS 9.1.1.4 and above
- ECOS 9.0.7.0 and above
- ECOS 8.3.7.0 and above
- Impact of this vulnerability on ECOS is very low.
Fixes will be applied only to the ECOS versions
that are listed above due to the minimal risk involved.
- Aruba EdgeConnect Enterprise Orchestrator (on-premises)
- Orchestrator does not use expat library. However:
- Customers using CentOS are suggested to run 'yum
update expat' from the administrative command line to
address this vulnerability; to verify if the patch has been
applied, run 'rpm -q --changelog expat' and look for
the specific CVEs. If the output shows 'Resolves', the
patches for the CVE(s) have already been applied.
- OR -
- Upgrading (from 9.0.6 or later) to any newer Orchestrator
version automatically updates expat and resolves this
vulnerability.
- New virtual machine images already have the fix for this
vulnerability.
- Customers using Fedora must upgrade to CentOS for support
of security updates. Please contact Customer Support for
the procedure.
- Aruba Virtual Intranet Access (VIA)
- Affects macOS/OSX versions only. Others are unaffected
- 4.4.0 and above
Aruba does not evaluate or patch product versions that have
reached their End of Support (EoS) milestone. For more
information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Jan 14, 2025 | May 17, 2022 |
| Aruba Aos 8 | — | - AirWave Management Platform
- 8.2.14.1 and above
- Aruba Analytics and Location Engine
- 2.2.0.3 and above
Release ETA - late July 2022
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.2.1 and above
- Aruba Central On-Premises
-2.5.5.0 and above
Release ETA - late July 2022
- Aruba ClearPass Policy Manager
- 6.10.5 and above
- 6.9.11 and above
- 6.8.9 with Hotfix for Q1 2022 Security issues applied
- ArubaOS-CX Switches
- 10.10.0002 and above
- 10.09.1031 and above
- 10.08.1070 and above
- 10.07.0080 and above
- 10.06.0210 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- Please note that this only affected controllers and
gateways based on the x86 architecture
This includes the following models
- Aruba 9000 Series Controllers
- Aruba 9200 Series Controllers
- Aruba Virtual Mobility Controllers
- Aruba Virtual and Hardware-based Mobility Conductors
-The fixed code versions are as follows
- ArubaOS 8.6.x: 8.6.0.19 and above
Release ETA - early September 2022
- ArubaOS 8.7.x: 8.7.1.10 and above
Release ETA - late July 2022
- ArubaOS 8.10.x: 8.10.0.3 and above
Release ETA - late August 2022
- ArubaOS 10.3.x: 10.3.1.1 and above
Release ETA - early August 2022
- SDWAN 2.X: 8.7.0.0-2.3.0.8 and above
Release ETA - late July 2022
- Aruba EdgeConnect Enterprise
- ECOS 9.1.1.4 and above
- ECOS 9.0.7.0 and above
- ECOS 8.3.7.0 and above
- Impact of this vulnerability on ECOS is very low.
Fixes will be applied only to the ECOS versions
that are listed above due to the minimal risk involved.
- Aruba EdgeConnect Enterprise Orchestrator (on-premises)
- Orchestrator does not use expat library. However:
- Customers using CentOS are suggested to run 'yum
update expat' from the administrative command line to
address this vulnerability; to verify if the patch has been
applied, run 'rpm -q --changelog expat' and look for
the specific CVEs. If the output shows 'Resolves', the
patches for the CVE(s) have already been applied.
- OR -
- Upgrading (from 9.0.6 or later) to any newer Orchestrator
version automatically updates expat and resolves this
vulnerability.
- New virtual machine images already have the fix for this
vulnerability.
- Customers using Fedora must upgrade to CentOS for support
of security updates. Please contact Customer Support for
the procedure.
- Aruba Virtual Intranet Access (VIA)
- Affects macOS/OSX versions only. Others are unaffected
- 4.4.0 and above
Aruba does not evaluate or patch product versions that have
reached their End of Support (EoS) milestone. For more
information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Jan 14, 2025 | May 17, 2022 |
| Aruba Aos Cx | — | - AirWave Management Platform
- 8.2.14.1 and above
- Aruba Analytics and Location Engine
- 2.2.0.3 and above
Release ETA - late July 2022
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.2.1 and above
- Aruba Central On-Premises
-2.5.5.0 and above
Release ETA - late July 2022
- Aruba ClearPass Policy Manager
- 6.10.5 and above
- 6.9.11 and above
- 6.8.9 with Hotfix for Q1 2022 Security issues applied
- ArubaOS-CX Switches
- 10.10.0002 and above
- 10.09.1031 and above
- 10.08.1070 and above
- 10.07.0080 and above
- 10.06.0210 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- Please note that this only affected controllers and
gateways based on the x86 architecture
This includes the following models
- Aruba 9000 Series Controllers
- Aruba 9200 Series Controllers
- Aruba Virtual Mobility Controllers
- Aruba Virtual and Hardware-based Mobility Conductors
-The fixed code versions are as follows
- ArubaOS 8.6.x: 8.6.0.19 and above
Release ETA - early September 2022
- ArubaOS 8.7.x: 8.7.1.10 and above
Release ETA - late July 2022
- ArubaOS 8.10.x: 8.10.0.3 and above
Release ETA - late August 2022
- ArubaOS 10.3.x: 10.3.1.1 and above
Release ETA - early August 2022
- SDWAN 2.X: 8.7.0.0-2.3.0.8 and above
Release ETA - late July 2022
- Aruba EdgeConnect Enterprise
- ECOS 9.1.1.4 and above
- ECOS 9.0.7.0 and above
- ECOS 8.3.7.0 and above
- Impact of this vulnerability on ECOS is very low.
Fixes will be applied only to the ECOS versions
that are listed above due to the minimal risk involved.
- Aruba EdgeConnect Enterprise Orchestrator (on-premises)
- Orchestrator does not use expat library. However:
- Customers using CentOS are suggested to run 'yum
update expat' from the administrative command line to
address this vulnerability; to verify if the patch has been
applied, run 'rpm -q --changelog expat' and look for
the specific CVEs. If the output shows 'Resolves', the
patches for the CVE(s) have already been applied.
- OR -
- Upgrading (from 9.0.6 or later) to any newer Orchestrator
version automatically updates expat and resolves this
vulnerability.
- New virtual machine images already have the fix for this
vulnerability.
- Customers using Fedora must upgrade to CentOS for support
of security updates. Please contact Customer Support for
the procedure.
- Aruba Virtual Intranet Access (VIA)
- Affects macOS/OSX versions only. Others are unaffected
- 4.4.0 and above
Aruba does not evaluate or patch product versions that have
reached their End of Support (EoS) milestone. For more
information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Feb 24, 2025 | May 17, 2022 |
| Centos_linux | — | Upgrade xmlrpc-c-clientUpgrade thunderbird-debuginfoUpgrade xmlrpc-c-client-debuginfoUpgrade xmlrpc-c-debuginfoUpgrade firefox-debuginfoUpgrade expat-debuginfoUpgrade thunderbird-debugsourceUpgrade xmlrpc-cUpgrade firefox-debugsourceUpgrade xmlrpc-c-apps-debuginfoUpgrade xmlrpc-c-c++-debuginfoUpgrade expat-develUpgrade expat-debugsourceUpgrade thunderbirdUpgrade firefoxUpgrade xmlrpc-c-debugsourceUpgrade expatUpgrade expat-static | Mar 11, 2022 | Feb 16, 2022 |
| Debian | — | Upgrade expat | Feb 24, 2022 | Feb 16, 2022 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Apr 30, 2022 |
| Gentoo Linux | — | Upgrade dev-libs/expat. | Sep 30, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp10 | — | Upgrade expat | Jun 7, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp3 | — | Upgrade expat-develUpgrade expat | May 25, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp5 | — | Upgrade expat-staticUpgrade expatUpgrade expat-devel | Apr 26, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp8 | — | Upgrade expatUpgrade expat-devel | Apr 26, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp9 | — | Upgrade expat | Jun 16, 2022 | Feb 16, 2022 |
| Ibm Aix | — | Apply the fix or workaround for python_advisory | Oct 12, 2022 | Feb 16, 2022 |
| Ibm Http_server | — | Apply IBM HTTP Server version 8.5.5.22 or laterApply IBM HTTP Server Interim Fix PH44271Apply IBM HTTP Server version 7.0.0.46 or laterApply IBM HTTP Server version 9.0.5.12 or laterApply IBM HTTP Server version 8.0.0.16 or later | Aug 31, 2022 | Mar 15, 2022 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Sep 4, 2023 |
| Oracle_linux | — | Upgrade firefoxUpgrade thunderbirdUpgrade xmlrpc-cUpgrade expatUpgrade expat-staticUpgrade xmlrpc-c-client++Upgrade xmlrpc-c-clientUpgrade expat-develUpgrade xmlrpc-c-c++ | Mar 11, 2022 | Feb 19, 2022 |
| Redhat_linux | — | No solution existsUpgrade thunderbird-debuginfoUpgrade xmlrpc-c-client-debuginfoUpgrade xmlrpc-c-develUpgrade thunderbirdUpgrade firefox-debuginfoUpgrade xmlrpc-cUpgrade firefoxUpgrade expat-debugsourceUpgrade xmlrpc-c-debugsourceUpgrade thunderbird-debugsourceUpgrade mingw32-expatUpgrade xmlrpc-c-c++-debuginfoUpgrade xmlrpc-c-apps-debuginfoUpgrade xmlrpc-c-debuginfoUpgrade expat-develUpgrade mingw32-expat-debuginfoUpgrade expatUpgrade expat-staticUpgrade xmlrpc-c-client++Upgrade mingw64-expat-debuginfoUpgrade firefox-debugsourceUpgrade xmlrpc-c-c++Upgrade mingw64-expatUpgrade expat-debuginfo | Mar 11, 2022 | Feb 16, 2022 |
| Rocky_linux | — | Upgrade xmlrpc-c-c++-debuginfoUpgrade xmlrpc-c-debugsourceUpgrade xmlrpc-c-clientUpgrade expat-debuginfoUpgrade xmlrpc-c-debuginfoUpgrade xmlrpc-c-client++-debuginfoUpgrade firefox-debugsourceUpgrade expatUpgrade xmlrpc-c-client++Upgrade thunderbirdUpgrade expat-debugsourceUpgrade xmlrpc-c-c++Upgrade xmlrpc-c-develUpgrade thunderbird-debuginfoUpgrade expat-develUpgrade xmlrpc-cUpgrade firefox-debuginfoUpgrade xmlrpc-c-client-debuginfoUpgrade firefoxUpgrade thunderbird-debugsource | Mar 5, 2024 | Feb 16, 2022 |
| Suse | — | Upgrade libexpat-develUpgrade libexpat-devel-32bitUpgrade expatUpgrade libexpat1-32bitUpgrade libexpat1 | Mar 4, 2022 | Feb 16, 2022 |
| Ubuntu | — | Upgrade libcoin80v5 (Ubuntu Pro)Upgrade libinsighttoolkit3.20 (Ubuntu Pro)Upgrade libxmlrpc-c++8v5 (Ubuntu Pro)Upgrade cableswig (Ubuntu Pro)Upgrade swish-e (Ubuntu Pro)Upgrade ayttm (Ubuntu Pro)Upgrade libxmlrpc-core-c3 (Ubuntu Pro)Upgrade libexpat1 (Ubuntu Pro)Upgrade lib64expat1 (Ubuntu Pro)Upgrade libxmlrpc-core-c3t64 (Ubuntu Pro)Upgrade libcoin80-runtime (Ubuntu Pro)Upgrade xmlrpc-api-utils (Ubuntu Pro)Upgrade libexpat1Upgrade libxmltok1 (Ubuntu Pro)Upgrade libxmlrpc-c++8t64 (Ubuntu Pro)Upgrade libcoin80 (Ubuntu Pro)Upgrade libxmlrpc-c++8 (Ubuntu Pro) | Feb 22, 2022 | Feb 16, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 16, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub