← Back

CVE-2024-28757

nvd nist
Published: Mar 10, 2024Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).

Affected (16)

Libexpat
1 product
Fedora
12 products
Active Iq Unified Manager
Oncommand Workflow Automation
Ontap
Ontap Tools
Windows Host Utilities
H300s Firmware
H500s Firmware
H700s Firmware
H410s Firmware
H410c Firmware
H610c Firmware
H610s Firmware
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.6.2
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 38
Version 39
Version 40
Configuration C
5 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
Version 9
Version 10
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H300s
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H500s
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H700s
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H410s
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H410c
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H610c
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H610s
All versions

References (17)

Source: cve@mitre.org
Mailing ListPatchRelease Notes
Source: cve@mitre.org
ExploitIssue TrackingPatch
Source: cve@mitre.org
Issue TrackingPatch
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.