First published: Sun Mar 10 2024(Updated: )
libexpat could allow a remote attacker to obtain sensitive information, caused by improper handling of XML external entity (XXE) declarations by the XML_ExternalEntityParserCreate function. By using a specially crafted XML content, a remote attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/expat | <=2.2.6-2+deb10u4<=2.2.6-2+deb10u7<=2.2.10-2+deb11u5<=2.5.0-1<=2.5.0-2 | 2.6.2-1 |
ubuntu/expat | <2.4.7-1ubuntu0.3 | 2.4.7-1ubuntu0.3 |
ubuntu/expat | <2.5.0-2ubuntu0.1 | 2.5.0-2ubuntu0.1 |
redhat/expat | <2.6.2 | 2.6.2 |
IBM Cognos Dashboards | <=5.0.0 | |
IBM Cognos Dashboards | <=4.8.0 | |
Libexpat | <2.6.2 | |
Red Hat Fedora | =38 | |
Red Hat Fedora | =39 | |
Red Hat Fedora | =40 | |
NetApp Active IQ Unified Manager for VMware vSphere | ||
NetApp OnCommand Workflow Automation | ||
NetApp ONTAP | =9 | |
NetApp ONTAP Tools for VMware vSphere | =10 | |
NetApp Windows Host Utilities | ||
All of | ||
NetApp H300S Firmware | ||
NetApp H300S Firmware | ||
All of | ||
NetApp H500e Firmware | ||
NetApp H500e Firmware | ||
All of | ||
NetApp H700S | ||
NetApp H700S | ||
All of | ||
NetApp H410S | ||
NetApp H410S Firmware | ||
All of | ||
NetApp H410C | ||
NetApp H410C Firmware | ||
All of | ||
NetApp H610C | ||
NetApp H610C Firmware | ||
All of | ||
NetApp HCI H610S Firmware | ||
NetApp H610S Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28757 is classified as a medium severity vulnerability due to its potential to expose sensitive information.
To mitigate CVE-2024-28757, upgrade to libexpat version 2.6.2-1 on Debian, 2.4.7-1ubuntu0.3 on Ubuntu Jammy, or 2.6.2 on Red Hat.
CVE-2024-28757 can be exploited through specially crafted XML content leveraging XML external entity (XXE) declarations.
CVE-2024-28757 affects libexpat versions up to 2.2.6-2+deb10u7 on Debian and various versions noted for Ubuntu and Red Hat.
CVE-2024-28757 is a remote vulnerability that requires an attacker to send specially crafted XML content to the target system.