ZeroHour

CVE-2024-40896

CVSS 3.1
9.1 critical
EPSS
1%p67
Published
()
Modified
Description

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.

Vendors
xmlsoftnetapp
Products
libxml2, hci compute node, solidfire \& hci management node, solidfire \& hci storage node, h300s firmware, h410s firmware, h500s firmware, h700s firmware, h410c firmware
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.