In Linaro Automated Validation Architecture (LAVA) before...
Moderate severity
Unreviewed
Published
Nov 18, 2022
to the GitHub Advisory Database
•
Updated Apr 29, 2025
Description
Published by the National Vulnerability Database
Nov 18, 2022
Published to the GitHub Advisory Database
Nov 18, 2022
Last updated
Apr 29, 2025
In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can submit crafted XMLRPC requests that cause a recursive XML entity expansion, leading to excessive use of memory on the server and a Denial of Service.
References