libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
libexpat hasta 2.6.1 permite un ataque de expansión de entidad XML cuando hay un uso aislado de analizadores externos (creados a través de XML_ExternalEntityParserCreate).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | NONE |
| Integrity Impact | NONE |
| Availability Impact | HIGH |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-776
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary |
en
CWE-776
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| libexpat_project | libexpat | * | <built-in method update of dict object at 0x7fd2a2792a00> | Application |
| fedoraproject | fedora | 38 | <built-in method update of dict object at 0x7fd3104e9100> | Operating System |
| fedoraproject | fedora | 39 | <built-in method update of dict object at 0x7fd368daa680> | Operating System |
| fedoraproject | fedora | 40 | <built-in method update of dict object at 0x7fd2d8284ec0> | Operating System |
| netapp | active_iq_unified_manager | - | <built-in method update of dict object at 0x7fd2a2791480> | Application |
| netapp | oncommand_workflow_automation | - | <built-in method update of dict object at 0x7fd340a96900> | Application |
| netapp | ontap | 9 | <built-in method update of dict object at 0x7fd340a952c0> | Application |
| netapp | ontap_tools | 10 | <built-in method update of dict object at 0x7fd36b13ba00> | Application |
| netapp | windows_host_utilities | - | <built-in method update of dict object at 0x7fd384634d80> | Application |
| netapp | h300s_firmware | - | <built-in method update of dict object at 0x7fd2a2791d80> | Operating System |
| netapp | h500s_firmware | - | <built-in method update of dict object at 0x7fd308705800> | Operating System |
| netapp | h700s_firmware | - | <built-in method update of dict object at 0x7fd340a95340> | Operating System |
| netapp | h410s_firmware | - | <built-in method update of dict object at 0x7fd3845f1a80> | Operating System |
| netapp | h410c_firmware | - | <built-in method update of dict object at 0x7fd38463a940> | Operating System |
| netapp | h610c_firmware | - | <built-in method update of dict object at 0x7fd38547c480> | Operating System |
| netapp | h610s_firmware | - | <built-in method update of dict object at 0x7fd36b3e63c0> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* |
| Yes | cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:netapp:ontap:9:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:* |
| Yes | cpe:2.3:a:netapp:windows_host_utilities:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:netapp:h610c_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:netapp:h610c:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:netapp:h610s_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:netapp:h610s:-:*:*:*:*:*:*:* |