Forum Discussion
libxml2 and CVE-2024-25062
Good day All,
Apologies for the silly question but I am new to F5, when I was running iHealth on my BigIP running V17.1.2.1 it flagged the above CVE-2024-25062. Is this for the version 17.1.0 - 17.1.2 which includes mine, in general? I am thinking this doesn't affect me because when I look in services (local traffic -> profiles -> services) I don't even see XML, unless I am looking in the wrong place. I also went into the command line did a find on libxml2 and xml2 and didn't find and directories. When I did a find on just xml I did find a few directories but nothing on xml2. So is it safe to say this doesn't affect me or am I wrong?
Thank you in advance!!
Warren
1 Reply
Hi,
It will affect on the components like "XML content-based routing, wap monitor, external monitor, AAM image optimization, ASM XML profiles". but the version V17.1.2.1 have so many another known vulnerabilities, if needed you can test and upgrade to 17.5
F5 Networks: CVE-2021-31566: K000140963: libarchive vulnerability CVE-2021-31566
F5 Networks: CVE-2022-43680: K000139525: Libexpat vulnerability CVE-2022-43680
F5 Networks: CVE-2023-52881: K000148479: Linux kernel vulnerability CVE-2023-52881
F5 Networks: CVE-2024-38477: K000140784: Apache HTTPD vulnerability CVE-2024-38477
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com