n libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.
| Link | Resource |
|---|---|
| https://gitlab.gnome.org/GNOME/libxml2/-/commit/1a8932303969907f6572b1b6aac4081c56adb5c6 | Issue Tracking |
| https://gitlab.gnome.org/GNOME/libxml2/-/issues/761 | Issue Tracking |
| https://security.netapp.com/advisory/ntap-20250228-0004/ | Third Party Advisory |
Configuration 1 (hide)
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
Configuration 8 (hide)
| AND |
|
25 Nov 2025, 13:32
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Netapp h300s
Netapp h410s Firmware Netapp h410c Firmware Netapp h700s Xmlsoft libxml2 Netapp h700s Firmware Netapp h500s Netapp solidfire \& Hci Management Node Netapp h410s Netapp hci Compute Node Netapp h300s Firmware Netapp h500s Firmware Netapp Xmlsoft Netapp h410c Netapp solidfire \& Hci Storage Node |
|
| References | () https://gitlab.gnome.org/GNOME/libxml2/-/commit/1a8932303969907f6572b1b6aac4081c56adb5c6 - Issue Tracking | |
| References | () https://gitlab.gnome.org/GNOME/libxml2/-/issues/761 - Issue Tracking | |
| References | () https://security.netapp.com/advisory/ntap-20250228-0004/ - Third Party Advisory | |
| CPE | cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:* cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:* cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:* cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:* |
28 Feb 2025, 13:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| References |
|
24 Dec 2024, 03:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
23 Dec 2024, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-611 |
23 Dec 2024, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2024-12-23 17:15
Updated : 2025-11-25 13:32
NVD link : CVE-2024-40896
Mitre link : CVE-2024-40896
CVE.ORG link : CVE-2024-40896
JSON object : View
Improper Restriction of XML External Entity Reference