xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade mingw32-expatUpgrade thunderbirdUpgrade expat-develUpgrade xmlrpc-c-client++Upgrade firefoxUpgrade expatUpgrade xmlrpc-c-c++Upgrade xmlrpc-c-develUpgrade mingw64-expat | May 4, 2022 | Feb 16, 2022 |
| Alpine Linux | — | Upgrade expat | Aug 22, 2024 | Feb 16, 2022 |
| Amazon Linux Ami 2 | — | Upgrade xmlrpc-cUpgrade xmlrpc-c-develUpgrade xmlrpc-c-debuginfoUpgrade xmlrpc-c-appsUpgrade xmlrpc-c-c++Upgrade expat-develUpgrade xmlrpc-c-client++Upgrade thunderbird-debuginfoUpgrade expat-staticUpgrade expat-debuginfoUpgrade thunderbirdUpgrade expat | Jul 4, 2022 | Feb 16, 2022 |
| Amazon_linux | — | Upgrade expatUpgrade xmlrpc-c | Mar 11, 2022 | Feb 16, 2022 |
| Amazon_linux_2023 | — | Upgrade xmlrpc-c-appsUpgrade expat-develUpgrade xmlrpc-c-c++Upgrade xmlrpc-c-debuginfoUpgrade xmlrpc-c-client++Upgrade xmlrpc-c-clientUpgrade xmlrpc-c-apps-debuginfoUpgrade xmlrpc-c-c++-debuginfoUpgrade expat-debuginfoUpgrade expat-staticUpgrade xmlrpc-cUpgrade expatUpgrade xmlrpc-c-client++-debuginfoUpgrade expat-debugsourceUpgrade xmlrpc-c-client-debuginfo | Feb 17, 2025 | Feb 19, 2022 |
| Aruba Aos 10 | — | - AirWave Management Platform
- 8.2.14.1 and above
- Aruba Analytics and Location Engine
- 2.2.0.3 and above
Release ETA - late July 2022
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.2.1 and above
- Aruba Central On-Premises
-2.5.5.0 and above
Release ETA - late July 2022
- Aruba ClearPass Policy Manager
- 6.10.5 and above
- 6.9.11 and above
- 6.8.9 with Hotfix for Q1 2022 Security issues applied
- ArubaOS-CX Switches
- 10.10.0002 and above
- 10.09.1031 and above
- 10.08.1070 and above
- 10.07.0080 and above
- 10.06.0210 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- Please note that this only affected controllers and
gateways based on the x86 architecture
This includes the following models
- Aruba 9000 Series Controllers
- Aruba 9200 Series Controllers
- Aruba Virtual Mobility Controllers
- Aruba Virtual and Hardware-based Mobility Conductors
-The fixed code versions are as follows
- ArubaOS 8.6.x: 8.6.0.19 and above
Release ETA - early September 2022
- ArubaOS 8.7.x: 8.7.1.10 and above
Release ETA - late July 2022
- ArubaOS 8.10.x: 8.10.0.3 and above
Release ETA - late August 2022
- ArubaOS 10.3.x: 10.3.1.1 and above
Release ETA - early August 2022
- SDWAN 2.X: 8.7.0.0-2.3.0.8 and above
Release ETA - late July 2022
- Aruba EdgeConnect Enterprise
- ECOS 9.1.1.4 and above
- ECOS 9.0.7.0 and above
- ECOS 8.3.7.0 and above
- Impact of this vulnerability on ECOS is very low.
Fixes will be applied only to the ECOS versions
that are listed above due to the minimal risk involved.
- Aruba EdgeConnect Enterprise Orchestrator (on-premises)
- Orchestrator does not use expat library. However:
- Customers using CentOS are suggested to run 'yum
update expat' from the administrative command line to
address this vulnerability; to verify if the patch has been
applied, run 'rpm -q --changelog expat' and look for
the specific CVEs. If the output shows 'Resolves', the
patches for the CVE(s) have already been applied.
- OR -
- Upgrading (from 9.0.6 or later) to any newer Orchestrator
version automatically updates expat and resolves this
vulnerability.
- New virtual machine images already have the fix for this
vulnerability.
- Customers using Fedora must upgrade to CentOS for support
of security updates. Please contact Customer Support for
the procedure.
- Aruba Virtual Intranet Access (VIA)
- Affects macOS/OSX versions only. Others are unaffected
- 4.4.0 and above
Aruba does not evaluate or patch product versions that have
reached their End of Support (EoS) milestone. For more
information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Jan 14, 2025 | May 17, 2022 |
| Aruba Aos 8 | — | - AirWave Management Platform
- 8.2.14.1 and above
- Aruba Analytics and Location Engine
- 2.2.0.3 and above
Release ETA - late July 2022
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.2.1 and above
- Aruba Central On-Premises
-2.5.5.0 and above
Release ETA - late July 2022
- Aruba ClearPass Policy Manager
- 6.10.5 and above
- 6.9.11 and above
- 6.8.9 with Hotfix for Q1 2022 Security issues applied
- ArubaOS-CX Switches
- 10.10.0002 and above
- 10.09.1031 and above
- 10.08.1070 and above
- 10.07.0080 and above
- 10.06.0210 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- Please note that this only affected controllers and
gateways based on the x86 architecture
This includes the following models
- Aruba 9000 Series Controllers
- Aruba 9200 Series Controllers
- Aruba Virtual Mobility Controllers
- Aruba Virtual and Hardware-based Mobility Conductors
-The fixed code versions are as follows
- ArubaOS 8.6.x: 8.6.0.19 and above
Release ETA - early September 2022
- ArubaOS 8.7.x: 8.7.1.10 and above
Release ETA - late July 2022
- ArubaOS 8.10.x: 8.10.0.3 and above
Release ETA - late August 2022
- ArubaOS 10.3.x: 10.3.1.1 and above
Release ETA - early August 2022
- SDWAN 2.X: 8.7.0.0-2.3.0.8 and above
Release ETA - late July 2022
- Aruba EdgeConnect Enterprise
- ECOS 9.1.1.4 and above
- ECOS 9.0.7.0 and above
- ECOS 8.3.7.0 and above
- Impact of this vulnerability on ECOS is very low.
Fixes will be applied only to the ECOS versions
that are listed above due to the minimal risk involved.
- Aruba EdgeConnect Enterprise Orchestrator (on-premises)
- Orchestrator does not use expat library. However:
- Customers using CentOS are suggested to run 'yum
update expat' from the administrative command line to
address this vulnerability; to verify if the patch has been
applied, run 'rpm -q --changelog expat' and look for
the specific CVEs. If the output shows 'Resolves', the
patches for the CVE(s) have already been applied.
- OR -
- Upgrading (from 9.0.6 or later) to any newer Orchestrator
version automatically updates expat and resolves this
vulnerability.
- New virtual machine images already have the fix for this
vulnerability.
- Customers using Fedora must upgrade to CentOS for support
of security updates. Please contact Customer Support for
the procedure.
- Aruba Virtual Intranet Access (VIA)
- Affects macOS/OSX versions only. Others are unaffected
- 4.4.0 and above
Aruba does not evaluate or patch product versions that have
reached their End of Support (EoS) milestone. For more
information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Jan 14, 2025 | May 17, 2022 |
| Aruba Aos Cx | — | - AirWave Management Platform
- 8.2.14.1 and above
- Aruba Analytics and Location Engine
- 2.2.0.3 and above
Release ETA - late July 2022
- Aruba Fabric Composer (AFC) and Plexxi Composable Fabric Manager (CFM)
- 6.2.1 and above
- Aruba Central On-Premises
-2.5.5.0 and above
Release ETA - late July 2022
- Aruba ClearPass Policy Manager
- 6.10.5 and above
- 6.9.11 and above
- 6.8.9 with Hotfix for Q1 2022 Security issues applied
- ArubaOS-CX Switches
- 10.10.0002 and above
- 10.09.1031 and above
- 10.08.1070 and above
- 10.07.0080 and above
- 10.06.0210 and above
- ArubaOS Wi-Fi Controllers and Gateways
- ArubaOS SD-WAN Gateways
- Please note that this only affected controllers and
gateways based on the x86 architecture
This includes the following models
- Aruba 9000 Series Controllers
- Aruba 9200 Series Controllers
- Aruba Virtual Mobility Controllers
- Aruba Virtual and Hardware-based Mobility Conductors
-The fixed code versions are as follows
- ArubaOS 8.6.x: 8.6.0.19 and above
Release ETA - early September 2022
- ArubaOS 8.7.x: 8.7.1.10 and above
Release ETA - late July 2022
- ArubaOS 8.10.x: 8.10.0.3 and above
Release ETA - late August 2022
- ArubaOS 10.3.x: 10.3.1.1 and above
Release ETA - early August 2022
- SDWAN 2.X: 8.7.0.0-2.3.0.8 and above
Release ETA - late July 2022
- Aruba EdgeConnect Enterprise
- ECOS 9.1.1.4 and above
- ECOS 9.0.7.0 and above
- ECOS 8.3.7.0 and above
- Impact of this vulnerability on ECOS is very low.
Fixes will be applied only to the ECOS versions
that are listed above due to the minimal risk involved.
- Aruba EdgeConnect Enterprise Orchestrator (on-premises)
- Orchestrator does not use expat library. However:
- Customers using CentOS are suggested to run 'yum
update expat' from the administrative command line to
address this vulnerability; to verify if the patch has been
applied, run 'rpm -q --changelog expat' and look for
the specific CVEs. If the output shows 'Resolves', the
patches for the CVE(s) have already been applied.
- OR -
- Upgrading (from 9.0.6 or later) to any newer Orchestrator
version automatically updates expat and resolves this
vulnerability.
- New virtual machine images already have the fix for this
vulnerability.
- Customers using Fedora must upgrade to CentOS for support
of security updates. Please contact Customer Support for
the procedure.
- Aruba Virtual Intranet Access (VIA)
- Affects macOS/OSX versions only. Others are unaffected
- 4.4.0 and above
Aruba does not evaluate or patch product versions that have
reached their End of Support (EoS) milestone. For more
information about Aruba's End of Support policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Feb 24, 2025 | May 17, 2022 |
| Centos_linux | — | Upgrade thunderbirdUpgrade expat-debugsourceUpgrade expat-staticUpgrade firefoxUpgrade xmlrpc-c-debugsourceUpgrade expatUpgrade xmlrpc-c-clientUpgrade xmlrpc-cUpgrade thunderbird-debugsourceUpgrade xmlrpc-c-c++-debuginfoUpgrade xmlrpc-c-apps-debuginfoUpgrade expat-debuginfoUpgrade expat-develUpgrade firefox-debuginfoUpgrade thunderbird-debuginfoUpgrade xmlrpc-c-debuginfoUpgrade xmlrpc-c-client-debuginfoUpgrade firefox-debugsource | Mar 11, 2022 | Feb 16, 2022 |
| Debian | — | Upgrade expat | Feb 24, 2022 | Feb 16, 2022 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Apr 30, 2022 |
| Gentoo Linux | — | Upgrade dev-libs/expat. | Sep 30, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp10 | — | Upgrade expat | Jun 7, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp3 | — | Upgrade expat-develUpgrade expat | May 25, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp5 | — | Upgrade expat-staticUpgrade expatUpgrade expat-devel | Apr 26, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp8 | — | Upgrade expat-develUpgrade expat | Apr 26, 2022 | Feb 16, 2022 |
| Huawei Euleros 2_0_sp9 | — | Upgrade expat | Jun 16, 2022 | Feb 16, 2022 |
| Ibm Aix | — | Apply the fix or workaround for python_advisory | Oct 12, 2022 | Feb 16, 2022 |
| Ibm Http_server | — | Apply IBM HTTP Server version 8.5.5.22 or laterApply IBM HTTP Server Interim Fix PH44271Apply IBM HTTP Server version 7.0.0.46 or laterApply IBM HTTP Server version 8.0.0.16 or laterApply IBM HTTP Server version 9.0.5.12 or later | Aug 31, 2022 | Mar 15, 2022 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Sep 4, 2023 |
| Oracle_linux | — | Upgrade expat-develUpgrade expat-staticUpgrade xmlrpc-c-c++Upgrade xmlrpc-c-client++Upgrade xmlrpc-c-clientUpgrade firefoxUpgrade xmlrpc-cUpgrade expatUpgrade thunderbird | Mar 11, 2022 | Feb 19, 2022 |
| Redhat_linux | — | Upgrade xmlrpc-c-client-debuginfoUpgrade thunderbird-debugsourceUpgrade xmlrpc-cUpgrade mingw32-expatUpgrade xmlrpc-c-develUpgrade thunderbirdUpgrade thunderbird-debuginfoUpgrade expat-debugsourceNo solution existsUpgrade firefoxUpgrade xmlrpc-c-debugsourceUpgrade firefox-debuginfoUpgrade expat-develUpgrade xmlrpc-c-apps-debuginfoUpgrade expat-debuginfoUpgrade xmlrpc-c-c++-debuginfoUpgrade xmlrpc-c-debuginfoUpgrade mingw64-expat-debuginfoUpgrade firefox-debugsourceUpgrade expatUpgrade mingw64-expatUpgrade mingw32-expat-debuginfoUpgrade xmlrpc-c-c++Upgrade xmlrpc-c-client++Upgrade expat-static | Mar 11, 2022 | Feb 16, 2022 |
| Rocky_linux | — | Upgrade xmlrpc-cUpgrade thunderbird-debugsourceUpgrade firefoxUpgrade expat-develUpgrade thunderbirdUpgrade xmlrpc-c-client-debuginfoUpgrade xmlrpc-c-develUpgrade expat-debugsourceUpgrade thunderbird-debuginfoUpgrade xmlrpc-c-c++Upgrade firefox-debuginfoUpgrade xmlrpc-c-client++Upgrade xmlrpc-c-debugsourceUpgrade expat-debuginfoUpgrade xmlrpc-c-debuginfoUpgrade expatUpgrade xmlrpc-c-clientUpgrade xmlrpc-c-c++-debuginfoUpgrade firefox-debugsourceUpgrade xmlrpc-c-client++-debuginfo | Mar 5, 2024 | Feb 16, 2022 |
| Suse | — | Upgrade libexpat-devel-32bitUpgrade libexpat-develUpgrade expatUpgrade libexpat1Upgrade libexpat1-32bit | Mar 4, 2022 | Feb 16, 2022 |
| Ubuntu | — | Upgrade libxmlrpc-c++8 (Ubuntu Pro)Upgrade libcoin80-runtime (Ubuntu Pro)Upgrade xmlrpc-api-utils (Ubuntu Pro)Upgrade libxmltok1 (Ubuntu Pro)Upgrade libexpat1Upgrade libxmlrpc-c++8t64 (Ubuntu Pro)Upgrade libcoin80 (Ubuntu Pro)Upgrade lib64expat1 (Ubuntu Pro)Upgrade libcoin80v5 (Ubuntu Pro)Upgrade libxmlrpc-core-c3t64 (Ubuntu Pro)Upgrade cableswig (Ubuntu Pro)Upgrade ayttm (Ubuntu Pro)Upgrade swish-e (Ubuntu Pro)Upgrade libexpat1 (Ubuntu Pro)Upgrade libxmlrpc-core-c3 (Ubuntu Pro)Upgrade libxmlrpc-c++8v5 (Ubuntu Pro)Upgrade libinsighttoolkit3.20 (Ubuntu Pro) | Feb 22, 2022 | Feb 16, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 16, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub