Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can submit crafted XMLRPC requests that cause a recursive XML entity expansion, leading to excessive use of memory on the server and a Denial of Service.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LAVA 安全漏洞
Vulnerability Description
LAVA是LAVA开源的一个持续集成系统。用于将操作系统部署到物理和虚拟硬件上以运行测试。 LAVA 2022.11之前的版本存在安全漏洞,该漏洞源于拥有有效凭证的用户可以提交精心编写的XMLRPC请求实现递归XML实体扩展,导致服务器上内存的过度使用和拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A