CVE-2024-28757

Severity
7.5HIGH
EPSS
1.2%
top 21.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 10
Latest updateMar 18

Description

libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

Debianexpat< 2.6.1-2+1
Ubuntuexpat< 2.4.7-1ubuntu0.3

Also affects: Ontap 9, Ontap Tools 10, Fedora 38, 39, 40

Patches

🔴Vulnerability Details

4
OSV
expat vulnerabilities2024-03-14
CVEList
CVE-2024-28757: libexpat through 22024-03-10
OSV
CVE-2024-28757: libexpat through 22024-03-10
GHSA
GHSA-ch5v-h69f-mxc8: libexpat through 22024-03-10

📋Vendor Advisories

6
BSD
OpenBSD 7.4 Errata 015: SECURITY FIX2024-03-18
BSD
OpenBSD 7.3 Errata 027: SECURITY FIX2024-03-18
Ubuntu
Expat vulnerabilities2024-03-14
Microsoft
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).2024-03-12
Red Hat
expat: XML Entity Expansion2024-03-10