Description

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.

INFO

Published Date :

2024-12-23T00:00:00.000Z

Last Modified :

2025-02-28T13:07:30.165Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2024-40896 vulnerability.

Vendors Products
Netapp
  • H300s
  • H300s Firmware
  • H410c
  • H410c Firmware
  • H410s
  • H410s Firmware
  • H500s
  • H500s Firmware
  • H700s
  • H700s Firmware
  • Hci Compute Node
  • Solidfire \& Hci Management Node
  • Solidfire \& Hci Storage Node
Redhat
  • Enterprise Linux
Xmlsoft
  • Libxml2

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact