xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade expatUpgrade xmlrpc-c-c++Upgrade xmlrpc-c-develUpgrade mingw64-expatUpgrade firefoxUpgrade expat-develUpgrade mingw32-expatUpgrade xmlrpc-c-client++Upgrade thunderbird | May 4, 2022 | Feb 16, 2022 |
| Alpine Linux | — | Upgrade expat | Aug 22, 2024 | Feb 16, 2022 |
| Amazon Linux Ami 2 | — | Upgrade xmlrpc-c-debuginfoUpgrade xmlrpc-c-appsUpgrade xmlrpc-c-client++Upgrade xmlrpc-c-c++Upgrade xmlrpc-c-develUpgrade thunderbird-debuginfoUpgrade expat-develUpgrade xmlrpc-cUpgrade expat-staticUpgrade expatUpgrade thunderbirdUpgrade expat-debuginfo | Jul 4, 2022 | Feb 16, 2022 |
| Amazon_linux | — | Upgrade expatUpgrade xmlrpc-c | Mar 11, 2022 | Feb 16, 2022 |
| Amazon_linux_2023 | — | Upgrade xmlrpc-c-apps-debuginfoUpgrade expat-develUpgrade xmlrpc-c-c++Upgrade xmlrpc-c-clientUpgrade xmlrpc-c-debuginfoUpgrade xmlrpc-c-c++-debuginfoUpgrade xmlrpc-c-client++Upgrade xmlrpc-c-appsUpgrade expat-debuginfoUpgrade xmlrpc-c-client-debuginfoUpgrade expat-debugsourceUpgrade xmlrpc-cUpgrade expatUpgrade expat-staticUpgrade xmlrpc-c-client++-debuginfo | Feb 17, 2025 | Feb 19, 2022 |
| Aruba Aos 10 | — | - AirWave Management Platform
- 8.2.14.1 and above
- Aruba Analytics and Location Engine
- 2.2.0.3 and above
Release ETA - late July 2022
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.2.1 and above
- Aruba Central On-Premises
-2.5.5.0 and above
Release ETA - late July 2022
- Aruba ClearPass Policy Manager
- 6.10.5 and above
- 6.9.11 and above
- 6.8.9 with Hotfix for Q1 2022 Security issues applied
- ArubaOS-CX Switches
- 10.10.0002 and above
- 10.09.1031 and above
- 10.08.1070 and above
- 10.07.0080 and above
- 10.06.0210 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- Please note that this only affected controllers and
gateways based on the x86 architecture
This includes the following models
- Aruba 9000 Series Controllers
- Aruba 9200 Series Controllers
- Aruba Virtual Mobility Controllers
- Aruba Virtual and Hardware-based Mobility Conductors
-The fixed code versions are as follows
- ArubaOS 8.6.x: 8.6.0.19 and above
Release ETA - early September 2022
- ArubaOS 8.7.x: 8.7.1.10 and above
Release ETA - late July 2022
- ArubaOS 8.10.x: 8.10.0.3 and above
Release ETA - late August 2022
- ArubaOS 10.3.x: 10.3.1.1 and above
Release ETA - early August 2022
- SDWAN 2.X: 8.7.0.0-2.3.0.8 and above
Release ETA - late July 2022
- Aruba EdgeConnect Enterprise
- ECOS 9.1.1.4 and above
- ECOS 9.0.7.0 and above
- ECOS 8.3.7.0 and above
- Impact of this vulnerability on ECOS is very low.
Fixes will be applied only to the ECOS versions
that are listed above due to the minimal risk involved.
- Aruba EdgeConnect Enterprise Orchestrator (on-premises)
- Orchestrator does not use expat library. However:
- Customers using CentOS are suggested to run 'yum
update expat' from the administrative command line to
address this vulnerability; to verify if the patch has been
applied, run 'rpm -q --changelog expat' and look for
the specific CVEs. If the output shows 'Resolves', the
patches for the CVE(s) have already been applied.
- OR -
- Upgrading (from 9.0.6 or later) to any newer Orchestrator
version automatically updates expat and resolves this
vulnerability.
- New virtual machine images already have the fix for this
vulnerability.
- Customers using Fedora must upgrade to CentOS for support
of security updates. Please contact Customer Support for
the procedure.
- Aruba Virtual Intranet Access (VIA)
- Affects macOS/OSX versions only. Others are unaffected
- 4.4.0 and above
Aruba does not evaluate or patch product versions that have
reached their End of Support (EoS) milestone. For more
information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Jan 14, 2025 | May 17, 2022 |
| Aruba Aos 8 | — | - AirWave Management Platform
- 8.2.14.1 and above
- Aruba Analytics and Location Engine
- 2.2.0.3 and above
Release ETA - late July 2022
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.2.1 and above
- Aruba Central On-Premises
-2.5.5.0 and above
Release ETA - late July 2022
- Aruba ClearPass Policy Manager
- 6.10.5 and above
- 6.9.11 and above
- 6.8.9 with Hotfix for Q1 2022 Security issues applied
- ArubaOS-CX Switches
- 10.10.0002 and above
- 10.09.1031 and above
- 10.08.1070 and above
- 10.07.0080 and above
- 10.06.0210 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- Please note that this only affected controllers and
gateways based on the x86 architecture
This includes the following models
- Aruba 9000 Series Controllers
- Aruba 9200 Series Controllers
- Aruba Virtual Mobility Controllers
- Aruba Virtual and Hardware-based Mobility Conductors
-The fixed code versions are as follows
- ArubaOS 8.6.x: 8.6.0.19 and above
Release ETA - early September 2022
- ArubaOS 8.7.x: 8.7.1.10 and above
Release ETA - late July 2022
- ArubaOS 8.10.x: 8.10.0.3 and above
Release ETA - late August 2022
- ArubaOS 10.3.x: 10.3.1.1 and above
Release ETA - early August 2022
- SDWAN 2.X: 8.7.0.0-2.3.0.8 and above
Release ETA - late July 2022
- Aruba EdgeConnect Enterprise
- ECOS 9.1.1.4 and above
- ECOS 9.0.7.0 and above
- ECOS 8.3.7.0 and above
- Impact of this vulnerability on ECOS is very low.
Fixes will be applied only to the ECOS versions
that are listed above due to the minimal risk involved.
- Aruba EdgeConnect Enterprise Orchestrator (on-premises)
- Orchestrator does not use expat library. However:
- Customers using CentOS are suggested to run 'yum
update expat' from the administrative command line to
address this vulnerability; to verify if the patch has been
applied, run 'rpm -q --changelog expat' and look for
the specific CVEs. If the output shows 'Resolves', the
patches for the CVE(s) have already been applied.
- OR -
- Upgrading (from 9.0.6 or later) to any newer Orchestrator
version automatically updates expat and resolves this
vulnerability.
- New virtual machine images already have the fix for this
vulnerability.
- Customers using Fedora must upgrade to CentOS for support
of security updates. Please contact Customer Support for
the procedure.
- Aruba Virtual Intranet Access (VIA)
- Affects macOS/OSX versions only. Others are unaffected
- 4.4.0 and above
Aruba does not evaluate or patch product versions that have
reached their End of Support (EoS) milestone. For more
information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Jan 14, 2025 | May 17, 2022 |
| Aruba Aos Cx | — | - AirWave Management Platform
- 8.2.14.1 and above
- Aruba Analytics and Location Engine
- 2.2.0.3 and above
Release ETA - late July 2022
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.2.1 and above
- Aruba Central On-Premises
-2.5.5.0 and above
Release ETA - late July 2022
- Aruba ClearPass Policy Manager
- 6.10.5 and above
- 6.9.11 and above
- 6.8.9 with Hotfix for Q1 2022 Security issues applied
- ArubaOS-CX Switches
- 10.10.0002 and above
- 10.09.1031 and above
- 10.08.1070 and above
- 10.07.0080 and above
- 10.06.0210 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- Please note that this only affected controllers and
gateways based on the x86 architecture
This includes the following models
- Aruba 9000 Series Controllers
- Aruba 9200 Series Controllers
- Aruba Virtual Mobility Controllers
- Aruba Virtual and Hardware-based Mobility Conductors
-The fixed code versions are as follows
- ArubaOS 8.6.x: 8.6.0.19 and above
Release ETA - early September 2022
- ArubaOS 8.7.x: 8.7.1.10 and above
Release ETA - late July 2022
- ArubaOS 8.10.x: 8.10.0.3 and above
Release ETA - late August 2022
- ArubaOS 10.3.x: 10.3.1.1 and above
Release ETA - early August 2022
- SDWAN 2.X: 8.7.0.0-2.3.0.8 and above
Release ETA - late July 2022
- Aruba EdgeConnect Enterprise
- ECOS 9.1.1.4 and above
- ECOS 9.0.7.0 and above
- ECOS 8.3.7.0 and above
- Impact of this vulnerability on ECOS is very low.
Fixes will be applied only to the ECOS versions
that are listed above due to the minimal risk involved.
- Aruba EdgeConnect Enterprise Orchestrator (on-premises)
- Orchestrator does not use expat library. However:
- Customers using CentOS are suggested to run 'yum
update expat' from the administrative command line to
address this vulnerability; to verify if the patch has been
applied, run 'rpm -q --changelog expat' and look for
the specific CVEs. If the output shows 'Resolves', the
patches for the CVE(s) have already been applied.
- OR -
- Upgrading (from 9.0.6 or later) to any newer Orchestrator
version automatically updates expat and resolves this
vulnerability.
- New virtual machine images already have the fix for this
vulnerability.
- Customers using Fedora must upgrade to CentOS for support
of security updates. Please contact Customer Support for
the procedure.
- Aruba Virtual Intranet Access (VIA)
- Affects macOS/OSX versions only. Others are unaffected
- 4.4.0 and above
Aruba does not evaluate or patch product versions that have
reached their End of Support (EoS) milestone. For more
information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Feb 24, 2025 | May 17, 2022 |
| Centos_linux | — | Upgrade thunderbirdUpgrade expat-debugsourceUpgrade xmlrpc-c-debugsourceUpgrade expat-staticUpgrade expatUpgrade firefoxUpgrade thunderbird-debugsourceUpgrade expat-develUpgrade xmlrpc-c-apps-debuginfoUpgrade xmlrpc-c-client-debuginfoUpgrade firefox-debugsourceUpgrade xmlrpc-cUpgrade firefox-debuginfoUpgrade expat-debuginfoUpgrade xmlrpc-c-c++-debuginfoUpgrade thunderbird-debuginfoUpgrade xmlrpc-c-clientUpgrade xmlrpc-c-debuginfo | Mar 11, 2022 | Feb 16, 2022 |
| Debian | — | Upgrade expat | Feb 24, 2022 | Feb 16, 2022 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Apr 30, 2022 |
| Gentoo Linux | — | Upgrade dev-libs/expat. | Sep 30, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp10 | — | Upgrade expat | Jun 7, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp3 | — | Upgrade expatUpgrade expat-devel | May 25, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp5 | — | Upgrade expatUpgrade expat-develUpgrade expat-static | Apr 26, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp8 | — | Upgrade expatUpgrade expat-devel | Apr 26, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp9 | — | Upgrade expat | Jun 16, 2022 | Feb 16, 2022 |
| Ibm Aix | — | Apply the fix or workaround for python_advisory | Oct 12, 2022 | Feb 16, 2022 |
| Ibm Http_server | — | Apply IBM HTTP Server version 8.0.0.16 or laterApply IBM HTTP Server version 8.5.5.22 or laterApply IBM HTTP Server version 9.0.5.12 or laterApply IBM HTTP Server Interim Fix PH44271Apply IBM HTTP Server version 7.0.0.46 or later | Aug 31, 2022 | Mar 15, 2022 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Sep 4, 2023 |
| Oracle_linux | — | Upgrade xmlrpc-c-client++Upgrade expat-develUpgrade xmlrpc-c-c++Upgrade expat-staticUpgrade xmlrpc-c-clientUpgrade expatUpgrade firefoxUpgrade xmlrpc-cUpgrade thunderbird | Mar 11, 2022 | Feb 19, 2022 |
| Redhat_linux | — | Upgrade firefoxUpgrade xmlrpc-c-debugsourceNo solution existsUpgrade expat-debugsourceUpgrade firefox-debuginfoUpgrade xmlrpc-cUpgrade thunderbird-debuginfoUpgrade thunderbirdUpgrade mingw32-expatUpgrade thunderbird-debugsourceUpgrade xmlrpc-c-develUpgrade xmlrpc-c-client-debuginfoUpgrade firefox-debugsourceUpgrade xmlrpc-c-c++-debuginfoUpgrade mingw64-expat-debuginfoUpgrade xmlrpc-c-debuginfoUpgrade mingw32-expat-debuginfoUpgrade expat-debuginfoUpgrade expat-staticUpgrade xmlrpc-c-client++Upgrade mingw64-expatUpgrade expatUpgrade expat-develUpgrade xmlrpc-c-apps-debuginfoUpgrade xmlrpc-c-c++ | Mar 11, 2022 | Feb 16, 2022 |
| Rocky_linux | — | Upgrade xmlrpc-c-debuginfoUpgrade xmlrpc-c-client++-debuginfoUpgrade xmlrpc-c-debugsourceUpgrade expat-debuginfoUpgrade xmlrpc-c-clientUpgrade expatUpgrade xmlrpc-c-c++-debuginfoUpgrade xmlrpc-c-client++Upgrade firefox-debugsourceUpgrade expat-develUpgrade xmlrpc-c-client-debuginfoUpgrade xmlrpc-c-develUpgrade thunderbird-debuginfoUpgrade firefoxUpgrade thunderbird-debugsourceUpgrade thunderbirdUpgrade expat-debugsourceUpgrade xmlrpc-c-c++Upgrade firefox-debuginfoUpgrade xmlrpc-c | Mar 5, 2024 | Feb 16, 2022 |
| Suse | — | Upgrade libexpat1-32bitUpgrade expatUpgrade libexpat1Upgrade libexpat-develUpgrade libexpat-devel-32bit | Mar 4, 2022 | Feb 16, 2022 |
| Ubuntu | — | Upgrade libcoin80-runtime (Ubuntu Pro)Upgrade libexpat1Upgrade libxmlrpc-c++8t64 (Ubuntu Pro)Upgrade libcoin80 (Ubuntu Pro)Upgrade libxmltok1 (Ubuntu Pro)Upgrade xmlrpc-api-utils (Ubuntu Pro)Upgrade libxmlrpc-c++8 (Ubuntu Pro)Upgrade swish-e (Ubuntu Pro)Upgrade libxmlrpc-c++8v5 (Ubuntu Pro)Upgrade libexpat1 (Ubuntu Pro)Upgrade ayttm (Ubuntu Pro)Upgrade libcoin80v5 (Ubuntu Pro)Upgrade libxmlrpc-core-c3 (Ubuntu Pro)Upgrade lib64expat1 (Ubuntu Pro)Upgrade libxmlrpc-core-c3t64 (Ubuntu Pro)Upgrade libinsighttoolkit3.20 (Ubuntu Pro)Upgrade cableswig (Ubuntu Pro) | Feb 22, 2022 | Feb 16, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 16, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub