ZeroHour

CVE-2024-28757

PoC
CVSS 3.1
7.5 high
EPSS
2%p80
Published
()
Modified
Description

libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).

Vendors
libexpat projectfedoraprojectnetapp
Products
libexpat, fedora, active iq unified manager, oncommand workflow automation, ontap, ontap tools, windows host utilities, h300s firmware, h500s firmware, h700s firmware, h410s firmware, h410c firmware
Weakness
CWE-776
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.