CRITICAL · 9.1

CVE-2024-40896

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by settin...

Vulnerability Description

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.

CVSS Score

9.1

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
XmlsoftLibxml2>= 2.11.0, < 2.11.9
NetappHci Compute Node-
NetappSolidfire \& Hci Management Node-
NetappSolidfire \& Hci Storage Node-
NetappH300S Firmware-
NetappH300S-
NetappH410S Firmware-
NetappH410S-
NetappH500S Firmware-
NetappH500S-
NetappH700S Firmware-
NetappH700S-
NetappH410C Firmware-
NetappH410C-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-40896?

CVE-2024-40896 is a vulnerability with a CVSS score of 9.1 (CRITICAL). In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by settin...

How severe is CVE-2024-40896?

CVE-2024-40896 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2024-40896?

Check the references section above for vendor advisories and patch information. Affected products include: Xmlsoft Libxml2, Netapp Hci Compute Node, Netapp Solidfire \& Hci Management Node, Netapp Solidfire \& Hci Storage Node, Netapp H300S Firmware.