In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Feb 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 24 Dec 2024 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | libxml2: XXE vulnerability | |
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Tue, 24 Dec 2024 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Mon, 23 Dec 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-611 |
Mon, 23 Dec 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2024-12-23T00:00:00.000Z
Updated: 2025-02-28T13:07:30.165Z
Reserved: 2024-07-12T00:00:00.000Z
Link: CVE-2024-40896

Updated: 2025-02-28T13:07:30.165Z

Status : Awaiting Analysis
Published: 2024-12-23T17:15:08.400
Modified: 2025-02-28T13:15:26.640
Link: CVE-2024-40896
