CVE-2021-38443
Published May 5, 2022Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML parser.
Vendor/product archive
2 CVEs tagged to eclipse / cyclonedds — 0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.
Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML parser.
Eclipse CycloneDDS versions prior to 0.8.0 are vulnerable to a write-what-where condition, which may allow an attacker to write arbitrary values in the XML parser.