cbcvebase.
CVE-2024-28757
published 2024-03-10

CVE-2024-28757: libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).

Affected

16 ranges
VendorProductVersion rangeFixed in
debianexpat< expat 2.6.1-2 (forky)expat 2.6.1-2 (forky)
debianlibxmltok< expat 2.6.1-2 (forky)expat 2.6.1-2 (forky)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
libexpat_projectlibexpat< 2.6.22.6.2
msrcazl3_cmake_3.30.3-6_on_azure_linux_3.0
msrcazl3_expat_2.5.0-1_on_azure_linux_3.0
msrcazl3_expat_2.6.2-1_on_azure_linux_3.0
msrcazl3_python3_3.12.3-5_on_azure_linux_3.0
msrccbl2_cmake_3.21.4-17_on_cbl_mariner_2.0
msrccbl2_expat_2.5.0-1_on_cbl_mariner_2.0
msrccbl2_expat_2.6.2-2_on_cbl_mariner_2.0
msrccbl2_python3_3.9.19-13_on_cbl_mariner_2.0
netappontap
netappontap_tools

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH