CVE-2024-40896

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*

History

25 Nov 2025, 13:32

Type Values Removed Values Added
First Time Netapp hci Compute Node
Netapp solidfire \& Hci Storage Node
Xmlsoft
Netapp h700s Firmware
Netapp h500s
Xmlsoft libxml2
Netapp
Netapp h700s
Netapp h300s
Netapp h500s Firmware
Netapp h410s
Netapp h410c
Netapp h410c Firmware
Netapp solidfire \& Hci Management Node
Netapp h410s Firmware
Netapp h300s Firmware
CPE cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*
References () https://gitlab.gnome.org/GNOME/libxml2/-/commit/1a8932303969907f6572b1b6aac4081c56adb5c6 - () https://gitlab.gnome.org/GNOME/libxml2/-/commit/1a8932303969907f6572b1b6aac4081c56adb5c6 - Issue Tracking
References () https://gitlab.gnome.org/GNOME/libxml2/-/issues/761 - () https://gitlab.gnome.org/GNOME/libxml2/-/issues/761 - Issue Tracking
References () https://security.netapp.com/advisory/ntap-20250228-0004/ - () https://security.netapp.com/advisory/ntap-20250228-0004/ - Third Party Advisory

28 Feb 2025, 13:15

Type Values Removed Values Added
Summary
  • (es) En libxml2 2.11 anterior a 2.11.9, 2.12 anterior a 2.12.9 y 2.13 anterior a 2.13.3, el analizador SAX puede producir eventos para entidades externas incluso si los controladores SAX personalizados intentan anular el contenido de la entidad (estableciendo "marcado"). Esto hace posibles los ataques XXE clásicos.
References
  • () https://security.netapp.com/advisory/ntap-20250228-0004/ -

24 Dec 2024, 03:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

23 Dec 2024, 18:15

Type Values Removed Values Added
CWE CWE-611

23 Dec 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-23 17:15

Updated : 2025-11-25 13:32


NVD link : CVE-2024-40896

Mitre link : CVE-2024-40896

CVE.ORG link : CVE-2024-40896


JSON object : View

Products Affected

netapp

  • h700s_firmware
  • solidfire_\&_hci_storage_node
  • solidfire_\&_hci_management_node
  • h300s
  • hci_compute_node
  • h700s
  • h410s
  • h500s_firmware
  • h410s_firmware
  • h300s_firmware
  • h410c_firmware
  • h410c
  • h500s

xmlsoft

  • libxml2
CWE
CWE-611

Improper Restriction of XML External Entity Reference