xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade xmlrpc-c-client++Upgrade expat-develUpgrade firefoxUpgrade mingw32-expatUpgrade thunderbirdUpgrade xmlrpc-c-develUpgrade xmlrpc-c-c++Upgrade expatUpgrade mingw64-expat | May 4, 2022 | Feb 16, 2022 |
| Alpine Linux | — | Upgrade expat | Aug 22, 2024 | Feb 16, 2022 |
| Amazon Linux Ami 2 | — | Upgrade xmlrpc-c-appsUpgrade xmlrpc-c-client++Upgrade thunderbird-debuginfoUpgrade xmlrpc-cUpgrade xmlrpc-c-develUpgrade expat-develUpgrade xmlrpc-c-c++Upgrade xmlrpc-c-debuginfoUpgrade expat-staticUpgrade expatUpgrade thunderbirdUpgrade expat-debuginfo | Jul 4, 2022 | Feb 16, 2022 |
| Amazon_linux | — | Upgrade xmlrpc-cUpgrade expat | Mar 11, 2022 | Feb 16, 2022 |
| Amazon_linux_2023 | — | Upgrade expat-debugsourceUpgrade expat-debuginfoUpgrade expatUpgrade xmlrpc-c-client++-debuginfoUpgrade xmlrpc-cUpgrade xmlrpc-c-client-debuginfoUpgrade expat-staticUpgrade xmlrpc-c-appsUpgrade xmlrpc-c-client++Upgrade xmlrpc-c-clientUpgrade xmlrpc-c-c++Upgrade xmlrpc-c-debuginfoUpgrade expat-develUpgrade xmlrpc-c-apps-debuginfoUpgrade xmlrpc-c-c++-debuginfo | Feb 17, 2025 | Feb 19, 2022 |
| Aruba Aos 10 | — | - AirWave Management Platform
- 8.2.14.1 and above
- Aruba Analytics and Location Engine
- 2.2.0.3 and above
Release ETA - late July 2022
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.2.1 and above
- Aruba Central On-Premises
-2.5.5.0 and above
Release ETA - late July 2022
- Aruba ClearPass Policy Manager
- 6.10.5 and above
- 6.9.11 and above
- 6.8.9 with Hotfix for Q1 2022 Security issues applied
- ArubaOS-CX Switches
- 10.10.0002 and above
- 10.09.1031 and above
- 10.08.1070 and above
- 10.07.0080 and above
- 10.06.0210 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- Please note that this only affected controllers and
gateways based on the x86 architecture
This includes the following models
- Aruba 9000 Series Controllers
- Aruba 9200 Series Controllers
- Aruba Virtual Mobility Controllers
- Aruba Virtual and Hardware-based Mobility Conductors
-The fixed code versions are as follows
- ArubaOS 8.6.x: 8.6.0.19 and above
Release ETA - early September 2022
- ArubaOS 8.7.x: 8.7.1.10 and above
Release ETA - late July 2022
- ArubaOS 8.10.x: 8.10.0.3 and above
Release ETA - late August 2022
- ArubaOS 10.3.x: 10.3.1.1 and above
Release ETA - early August 2022
- SDWAN 2.X: 8.7.0.0-2.3.0.8 and above
Release ETA - late July 2022
- Aruba EdgeConnect Enterprise
- ECOS 9.1.1.4 and above
- ECOS 9.0.7.0 and above
- ECOS 8.3.7.0 and above
- Impact of this vulnerability on ECOS is very low.
Fixes will be applied only to the ECOS versions
that are listed above due to the minimal risk involved.
- Aruba EdgeConnect Enterprise Orchestrator (on-premises)
- Orchestrator does not use expat library. However:
- Customers using CentOS are suggested to run 'yum
update expat' from the administrative command line to
address this vulnerability; to verify if the patch has been
applied, run 'rpm -q --changelog expat' and look for
the specific CVEs. If the output shows 'Resolves', the
patches for the CVE(s) have already been applied.
- OR -
- Upgrading (from 9.0.6 or later) to any newer Orchestrator
version automatically updates expat and resolves this
vulnerability.
- New virtual machine images already have the fix for this
vulnerability.
- Customers using Fedora must upgrade to CentOS for support
of security updates. Please contact Customer Support for
the procedure.
- Aruba Virtual Intranet Access (VIA)
- Affects macOS/OSX versions only. Others are unaffected
- 4.4.0 and above
Aruba does not evaluate or patch product versions that have
reached their End of Support (EoS) milestone. For more
information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Jan 14, 2025 | May 17, 2022 |
| Aruba Aos 8 | — | - AirWave Management Platform
- 8.2.14.1 and above
- Aruba Analytics and Location Engine
- 2.2.0.3 and above
Release ETA - late July 2022
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.2.1 and above
- Aruba Central On-Premises
-2.5.5.0 and above
Release ETA - late July 2022
- Aruba ClearPass Policy Manager
- 6.10.5 and above
- 6.9.11 and above
- 6.8.9 with Hotfix for Q1 2022 Security issues applied
- ArubaOS-CX Switches
- 10.10.0002 and above
- 10.09.1031 and above
- 10.08.1070 and above
- 10.07.0080 and above
- 10.06.0210 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- Please note that this only affected controllers and
gateways based on the x86 architecture
This includes the following models
- Aruba 9000 Series Controllers
- Aruba 9200 Series Controllers
- Aruba Virtual Mobility Controllers
- Aruba Virtual and Hardware-based Mobility Conductors
-The fixed code versions are as follows
- ArubaOS 8.6.x: 8.6.0.19 and above
Release ETA - early September 2022
- ArubaOS 8.7.x: 8.7.1.10 and above
Release ETA - late July 2022
- ArubaOS 8.10.x: 8.10.0.3 and above
Release ETA - late August 2022
- ArubaOS 10.3.x: 10.3.1.1 and above
Release ETA - early August 2022
- SDWAN 2.X: 8.7.0.0-2.3.0.8 and above
Release ETA - late July 2022
- Aruba EdgeConnect Enterprise
- ECOS 9.1.1.4 and above
- ECOS 9.0.7.0 and above
- ECOS 8.3.7.0 and above
- Impact of this vulnerability on ECOS is very low.
Fixes will be applied only to the ECOS versions
that are listed above due to the minimal risk involved.
- Aruba EdgeConnect Enterprise Orchestrator (on-premises)
- Orchestrator does not use expat library. However:
- Customers using CentOS are suggested to run 'yum
update expat' from the administrative command line to
address this vulnerability; to verify if the patch has been
applied, run 'rpm -q --changelog expat' and look for
the specific CVEs. If the output shows 'Resolves', the
patches for the CVE(s) have already been applied.
- OR -
- Upgrading (from 9.0.6 or later) to any newer Orchestrator
version automatically updates expat and resolves this
vulnerability.
- New virtual machine images already have the fix for this
vulnerability.
- Customers using Fedora must upgrade to CentOS for support
of security updates. Please contact Customer Support for
the procedure.
- Aruba Virtual Intranet Access (VIA)
- Affects macOS/OSX versions only. Others are unaffected
- 4.4.0 and above
Aruba does not evaluate or patch product versions that have
reached their End of Support (EoS) milestone. For more
information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Jan 14, 2025 | May 17, 2022 |
| Aruba Aos Cx | — | - AirWave Management Platform
- 8.2.14.1 and above
- Aruba Analytics and Location Engine
- 2.2.0.3 and above
Release ETA - late July 2022
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.2.1 and above
- Aruba Central On-Premises
-2.5.5.0 and above
Release ETA - late July 2022
- Aruba ClearPass Policy Manager
- 6.10.5 and above
- 6.9.11 and above
- 6.8.9 with Hotfix for Q1 2022 Security issues applied
- ArubaOS-CX Switches
- 10.10.0002 and above
- 10.09.1031 and above
- 10.08.1070 and above
- 10.07.0080 and above
- 10.06.0210 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- Please note that this only affected controllers and
gateways based on the x86 architecture
This includes the following models
- Aruba 9000 Series Controllers
- Aruba 9200 Series Controllers
- Aruba Virtual Mobility Controllers
- Aruba Virtual and Hardware-based Mobility Conductors
-The fixed code versions are as follows
- ArubaOS 8.6.x: 8.6.0.19 and above
Release ETA - early September 2022
- ArubaOS 8.7.x: 8.7.1.10 and above
Release ETA - late July 2022
- ArubaOS 8.10.x: 8.10.0.3 and above
Release ETA - late August 2022
- ArubaOS 10.3.x: 10.3.1.1 and above
Release ETA - early August 2022
- SDWAN 2.X: 8.7.0.0-2.3.0.8 and above
Release ETA - late July 2022
- Aruba EdgeConnect Enterprise
- ECOS 9.1.1.4 and above
- ECOS 9.0.7.0 and above
- ECOS 8.3.7.0 and above
- Impact of this vulnerability on ECOS is very low.
Fixes will be applied only to the ECOS versions
that are listed above due to the minimal risk involved.
- Aruba EdgeConnect Enterprise Orchestrator (on-premises)
- Orchestrator does not use expat library. However:
- Customers using CentOS are suggested to run 'yum
update expat' from the administrative command line to
address this vulnerability; to verify if the patch has been
applied, run 'rpm -q --changelog expat' and look for
the specific CVEs. If the output shows 'Resolves', the
patches for the CVE(s) have already been applied.
- OR -
- Upgrading (from 9.0.6 or later) to any newer Orchestrator
version automatically updates expat and resolves this
vulnerability.
- New virtual machine images already have the fix for this
vulnerability.
- Customers using Fedora must upgrade to CentOS for support
of security updates. Please contact Customer Support for
the procedure.
- Aruba Virtual Intranet Access (VIA)
- Affects macOS/OSX versions only. Others are unaffected
- 4.4.0 and above
Aruba does not evaluate or patch product versions that have
reached their End of Support (EoS) milestone. For more
information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Feb 24, 2025 | May 17, 2022 |
| Centos_linux | — | Upgrade xmlrpc-c-debugsourceUpgrade firefoxUpgrade expat-staticUpgrade expatUpgrade expat-debugsourceUpgrade thunderbirdUpgrade firefox-debuginfoUpgrade firefox-debugsourceUpgrade expat-develUpgrade xmlrpc-c-clientUpgrade thunderbird-debuginfoUpgrade xmlrpc-c-debuginfoUpgrade xmlrpc-cUpgrade thunderbird-debugsourceUpgrade expat-debuginfoUpgrade xmlrpc-c-client-debuginfoUpgrade xmlrpc-c-c++-debuginfoUpgrade xmlrpc-c-apps-debuginfo | Mar 11, 2022 | Feb 16, 2022 |
| Debian | — | Upgrade expat | Feb 24, 2022 | Feb 16, 2022 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Apr 30, 2022 |
| Gentoo Linux | — | Upgrade dev-libs/expat. | Sep 30, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp10 | — | Upgrade expat | Jun 7, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp3 | — | Upgrade expatUpgrade expat-devel | May 25, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp5 | — | Upgrade expat-develUpgrade expatUpgrade expat-static | Apr 26, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp8 | — | Upgrade expat-develUpgrade expat | Apr 26, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp9 | — | Upgrade expat | Jun 16, 2022 | Feb 16, 2022 |
| Ibm Aix | — | Apply the fix or workaround for python_advisory | Oct 12, 2022 | Feb 16, 2022 |
| Ibm Http_server | — | Apply IBM HTTP Server version 9.0.5.12 or laterApply IBM HTTP Server version 8.0.0.16 or laterApply IBM HTTP Server version 8.5.5.22 or laterApply IBM HTTP Server version 7.0.0.46 or laterApply IBM HTTP Server Interim Fix PH44271 | Aug 31, 2022 | Mar 15, 2022 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Sep 4, 2023 |
| Oracle_linux | — | Upgrade firefoxUpgrade xmlrpc-cUpgrade expatUpgrade thunderbirdUpgrade xmlrpc-c-c++Upgrade expat-develUpgrade xmlrpc-c-clientUpgrade expat-staticUpgrade xmlrpc-c-client++ | Mar 11, 2022 | Feb 19, 2022 |
| Redhat_linux | — | Upgrade firefox-debuginfoUpgrade xmlrpc-c-client-debuginfoUpgrade thunderbirdUpgrade xmlrpc-c-develUpgrade firefoxUpgrade expat-debugsourceNo solution existsUpgrade thunderbird-debugsourceUpgrade mingw32-expatUpgrade xmlrpc-c-debugsourceUpgrade xmlrpc-cUpgrade thunderbird-debuginfoUpgrade expat-debuginfoUpgrade mingw32-expat-debuginfoUpgrade xmlrpc-c-client++Upgrade xmlrpc-c-c++Upgrade firefox-debugsourceUpgrade mingw64-expat-debuginfoUpgrade mingw64-expatUpgrade expatUpgrade expat-staticUpgrade expat-develUpgrade xmlrpc-c-c++-debuginfoUpgrade xmlrpc-c-apps-debuginfoUpgrade xmlrpc-c-debuginfo | Mar 11, 2022 | Feb 16, 2022 |
| Rocky_linux | — | Upgrade expat-develUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfoUpgrade xmlrpc-c-develUpgrade xmlrpc-c-client-debuginfoUpgrade firefoxUpgrade firefox-debuginfoUpgrade expat-debugsourceUpgrade thunderbirdUpgrade xmlrpc-cUpgrade xmlrpc-c-c++Upgrade firefox-debugsourceUpgrade xmlrpc-c-client++-debuginfoUpgrade xmlrpc-c-client++Upgrade xmlrpc-c-clientUpgrade xmlrpc-c-c++-debuginfoUpgrade expatUpgrade expat-debuginfoUpgrade xmlrpc-c-debugsourceUpgrade xmlrpc-c-debuginfo | Mar 5, 2024 | Feb 16, 2022 |
| Suse | — | Upgrade libexpat1-32bitUpgrade libexpat1Upgrade expatUpgrade libexpat-devel-32bitUpgrade libexpat-devel | Mar 4, 2022 | Feb 16, 2022 |
| Ubuntu | — | Upgrade swish-e (Ubuntu Pro)Upgrade libexpat1 (Ubuntu Pro)Upgrade lib64expat1 (Ubuntu Pro)Upgrade libxmlrpc-c++8v5 (Ubuntu Pro)Upgrade libinsighttoolkit3.20 (Ubuntu Pro)Upgrade libxmlrpc-core-c3t64 (Ubuntu Pro)Upgrade libxmlrpc-core-c3 (Ubuntu Pro)Upgrade cableswig (Ubuntu Pro)Upgrade libcoin80v5 (Ubuntu Pro)Upgrade ayttm (Ubuntu Pro)Upgrade libcoin80 (Ubuntu Pro)Upgrade libxmltok1 (Ubuntu Pro)Upgrade xmlrpc-api-utils (Ubuntu Pro)Upgrade libexpat1Upgrade libcoin80-runtime (Ubuntu Pro)Upgrade libxmlrpc-c++8t64 (Ubuntu Pro)Upgrade libxmlrpc-c++8 (Ubuntu Pro) | Feb 22, 2022 | Feb 16, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 16, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub