CVE Vulnerabilities

CVE-2021-38443

Improper Handling of Syntactically Invalid Structure

Published: May 05, 2022 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML parser.

Weakness

The product does not handle or incorrectly handles input that is not syntactically well-formed with respect to the associated specification.

Affected Software

NameVendorStart VersionEnd Version
CycloneddsEclipse*0.8.0 (excluding)
CycloneddsUbuntuimpish*
CycloneddsUbuntukinetic*
CycloneddsUbuntulunar*
CycloneddsUbuntumantic*
CycloneddsUbuntuoracular*
CycloneddsUbuntuplucky*

References