Lucene search

K
f5F5F5:K51011533
HistoryJul 18, 2019 - 12:00 a.m.

K51011533 : Expat XML parser vulnerability CVE-2018-20843

2019-07-1800:00:00
my.f5.com
36

7.6 High

AI Score

Confidence

High

0.582 Medium

EPSS

Percentile

97.8%

Security Advisory Description

In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks). (CVE-2018-20843)

Impact

Users with valid administrative access can inject XML that consumes excessive system resources when parsed, potentially leading to reduced capacity or a failover event.