Description
In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can submit crafted XMLRPC requests that cause a recursive XML entity expansion, leading to excessive use of memory on the server and a Denial of Service.
References
https://lists.debian.org/debian-lts-announce/2023/01/msg00016.html
Mailing ListThird Party Advisory
https://www.debian.org/security/2023/dsa-5318
Third Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
6.5 · Medium
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
Vulnerability status
Modified
Published
2022-11-18T21:15:11.787
2 years agoLast modified
2023-11-07T03:54:22.733
1 year ago