CVE-2024-28757

libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
References
Link Resource
http://www.openwall.com/lists/oss-security/2024/03/15/1 Mailing List Patch Release Notes
https://github.com/libexpat/libexpat/issues/839 Exploit Issue Tracking Patch
https://github.com/libexpat/libexpat/pull/842 Issue Tracking Patch
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPLC6WDSRDUYS7F7JWAOVOHFNOUQ43DD/ Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKJ7V5F6LJCEQJXDBWGT27J7NAP3E3N7/ Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VK2O34GH43NTHBZBN7G5Y6YKJKPUCTBE/ Mailing List
https://security.netapp.com/advisory/ntap-20240322-0001/ Third Party Advisory
http://www.openwall.com/lists/oss-security/2024/03/15/1 Mailing List Patch Release Notes
https://github.com/libexpat/libexpat/issues/839 Exploit Issue Tracking Patch
https://github.com/libexpat/libexpat/pull/842 Issue Tracking Patch
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPLC6WDSRDUYS7F7JWAOVOHFNOUQ43DD/ Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKJ7V5F6LJCEQJXDBWGT27J7NAP3E3N7/ Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VK2O34GH43NTHBZBN7G5Y6YKJKPUCTBE/ Mailing List
https://lists.fedoraproject.org/archives/list/[email protected]/message/FPLC6WDSRDUYS7F7JWAOVOHFNOUQ43DD/
https://lists.fedoraproject.org/archives/list/[email protected]/message/LKJ7V5F6LJCEQJXDBWGT27J7NAP3E3N7/
https://lists.fedoraproject.org/archives/list/[email protected]/message/VK2O34GH43NTHBZBN7G5Y6YKJKPUCTBE/
https://security.netapp.com/advisory/ntap-20240322-0001/ Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:windows_host_utilities:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:netapp:h610c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h610c:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:netapp:h610s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h610s:-:*:*:*:*:*:*:*

History

04 Nov 2025, 22:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/[email protected]/message/FPLC6WDSRDUYS7F7JWAOVOHFNOUQ43DD/ -
  • () https://lists.fedoraproject.org/archives/list/[email protected]/message/LKJ7V5F6LJCEQJXDBWGT27J7NAP3E3N7/ -
  • () https://lists.fedoraproject.org/archives/list/[email protected]/message/VK2O34GH43NTHBZBN7G5Y6YKJKPUCTBE/ -

Information

Published : 2024-03-10 05:15

Updated : 2025-11-04 22:15


NVD link : CVE-2024-28757

Mitre link : CVE-2024-28757

CVE.ORG link : CVE-2024-28757


JSON object : View

Products Affected

netapp

  • h700s_firmware
  • h410s
  • h410c
  • windows_host_utilities
  • h500s_firmware
  • h610c_firmware
  • h610s
  • h610s_firmware
  • ontap
  • h500s
  • h410s_firmware
  • active_iq_unified_manager
  • h300s
  • h410c_firmware
  • ontap_tools
  • h300s_firmware
  • h700s
  • h610c
  • oncommand_workflow_automation

libexpat_project

  • libexpat

fedoraproject

  • fedora
CWE
CWE-776

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')