In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.
History

Tue, 24 Dec 2024 13:45:00 +0000

Type Values Removed Values Added
Title libxml2: XXE vulnerability
References
Metrics threat_severity

None

threat_severity

Critical


Tue, 24 Dec 2024 02:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Dec 2024 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-611

Mon, 23 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
Description In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-12-23T00:00:00

Updated: 2024-12-24T02:11:06.747Z

Reserved: 2024-07-12T00:00:00

Link: CVE-2024-40896

cve-icon Vulnrichment

Updated: 2024-12-24T02:11:00.509Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-12-23T17:15:08.400

Modified: 2024-12-24T03:15:06.727

Link: CVE-2024-40896

cve-icon Redhat

Severity : Critical

Publid Date: 2024-12-23T00:00:00Z

Links: CVE-2024-40896 - Bugzilla