CVE-2024-40896

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.
Configurations

No configuration.

History

28 Feb 2025, 13:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20250228-0004/ -
Summary
  • (es) En libxml2 2.11 anterior a 2.11.9, 2.12 anterior a 2.12.9 y 2.13 anterior a 2.13.3, el analizador SAX puede producir eventos para entidades externas incluso si los controladores SAX personalizados intentan anular el contenido de la entidad (estableciendo "marcado"). Esto hace posibles los ataques XXE clásicos.

24 Dec 2024, 03:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

23 Dec 2024, 18:15

Type Values Removed Values Added
CWE CWE-611

23 Dec 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-23 17:15

Updated : 2025-02-28 13:15


NVD link : CVE-2024-40896

Mitre link : CVE-2024-40896

CVE.ORG link : CVE-2024-40896


JSON object : View

Products Affected

No product.

CWE
CWE-611

Improper Restriction of XML External Entity Reference