XML External Entity injection in expat - CVE-2024-28757

 

XML External Entity injection in expat - CVE-2024-28757

Published: March 11, 2024 / Updated: May 21, 2025


Vulnerability identifier: #VU87337
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-28757
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to insufficient validation of user-supplied XML input when using external parsers via XML_ExternalEntityParserCreate. A remote attacker can pass a specially crafted XML code to the affected application and view contents of arbitrary files on the system or initiate requests to external systems.

Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary file on the server or perform network scanning of internal and external infrastructure.


Affected software

expat
Oracle Linux
Oracle Solaris
Amazon Linux AMI
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
OpenBSD
IBM AIX
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Slackware Linux
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Fedora
Cognos Dashboards on Cloud Pak for Data
Financial Transaction Manager for RedHat OpenShift
Tivoli Network Manager IP Edition
Db2 Big SQL
IBM OpenPages with Watson
Datacap
CICS Transaction Gateway for Multiplatforms
IBM OS Image for Red Hat Linux Systems
Storage Resource Manager
Storage Protect Server
Integrated System for Microsoft Azure Stack Hub
OpenShift API for Data Protection (OADP)
IBM Security Guardium Key Lifecycle Manager (GKLM)
WebSphere Remote Server
IBM Security Verify Governance
Run Once Duration Override Operator for Red Hat OpenShift
Red Hat Advanced Cluster Management for Kubernetes
IBM Cloud Transformation Advisor
Red Hat OpenShift Dev Spaces
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Kube Descheduler Operator for Red Hat OpenShift
App Connect Enterprise Certified Container
IBM Tivoli Business Service Manager
IBM Cloud Application Performance Management (APM)
IBM Cloud Pak for Business Automation
IBM Observability with Instana
IBM VIOS
iDRAC9
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
expat-debuginfo
expat
expat-debugsource
expat-devel
expat-help
libexpat1-64bit
libexpat1-32bit-debuginfo
libexpat-devel-32bit
expat-32bit-debuginfo
libexpat1-32bit
expat-64bit-debuginfo
libexpat-devel-64bit
libexpat1
libexpat1-debuginfo
libexpat-devel
libexpat1-64bit-debuginfo
libexpat1 (Ubuntu package)
expat (Ubuntu package)
expat (Red Hat package)
expat-static
expat-doc
mingw-expat
python3.8
python3
python3.9
python3.10
BIG-IP
PowerScale OneFS
HPE NonStop Virtual Tape Repository (VTR)
Red Hat OpenShift Serverless
IBM Cloud Pak System
Red Hat OpenShift Container Platform
Dell EMC Storage Monitoring and Reporting (SMR)
Dell EMC VxRail Appliance
IBM DB2
IBM CICS TX Standard

How to mitigate CVE-2024-28757

Install updates from vendor's website.

expat - update to 2.6.2
Oracle Solaris - update to 11.4 SRU 71
OpenShift API for Data Protection (OADP) - update to 1.3.1
Tivoli Network Manager IP Edition - update to 4.2.0.20
iDRAC9 - addressed in versions 7.00.00.184, 7.30.30.51
Db2 Big SQL - update to 7.6.8
BIG-IP - update to 17.1.2.2
HPE NonStop Virtual Tape Repository (VTR) - update to T09644V01^AAK
Red Hat OpenShift Serverless - update to 1
Run Once Duration Override Operator for Red Hat OpenShift - addressed in versions 1.1.2, 1.2.0
expat-debuginfo - update to 2.2.9-11
expat - update to 2.2.9-11
expat-debugsource - update to 2.2.9-11
expat-devel - update to 2.2.9-11
expat-help - update to 2.2.9-11
IBM Cloud Pak System - update to 2.3.4.1
libexpat1-64bit - update to 2.4.4-150400.3.17.1
libexpat1-32bit-debuginfo - update to 2.4.4-150400.3.17.1
libexpat-devel-32bit - update to 2.4.4-150400.3.17.1
expat-32bit-debuginfo - update to 2.4.4-150400.3.17.1
libexpat1-32bit - update to 2.4.4-150400.3.17.1
expat-64bit-debuginfo - update to 2.4.4-150400.3.17.1
libexpat-devel-64bit - update to 2.4.4-150400.3.17.1
libexpat1 - update to 2.4.4-150400.3.17.1
expat - update to 2.4.4-150400.3.17.1
libexpat1-debuginfo - update to 2.4.4-150400.3.17.1
expat-debugsource - update to 2.4.4-150400.3.17.1
expat-debuginfo - update to 2.4.4-150400.3.17.1
libexpat-devel - update to 2.4.4-150400.3.17.1
libexpat1-64bit-debuginfo - update to 2.4.4-150400.3.17.1
libexpat1 (Ubuntu package) - addressed in versions 2.4.7-1ubuntu0.3, 2.5.0-2ubuntu0.1
expat (Ubuntu package) - addressed in versions 2.4.7-1ubuntu0.3, 2.5.0-2ubuntu0.1
expat - update to 2.5.0-1
expat (Red Hat package) - addressed in versions 2.5.0-1.el9_2.1, 2.5.0-1.el9_3.1
expat-static - update to 2.5.0-4
expat-devel - update to 2.5.0-4
expat - update to 2.5.0-4
expat-doc - update to 2.5.0-4
mingw-expat - addressed in versions 2.6.1-1.fc38, 2.6.1-1.fc39, 2.6.1-1.fc40
expat - update to 2.6.2
Red Hat Advanced Cluster Management for Kubernetes - update to 2.10.4
python3.8 - addressed in versions 3.8.20-1.fc39, 3.8.20-1.fc40, 3.8.20-1.fc41
python3 - update to 3.9.20
python3.9 - addressed in versions 3.9.20-1.fc39, 3.9.20-1.fc40, 3.9.20-1.fc41
IBM Cloud Transformation Advisor - update to 3.10.0
python3.10 - addressed in versions 3.10.15-1.fc39, 3.10.15-1.fc40, 3.10.15-1.fc41
Red Hat OpenShift Dev Spaces - update to 3.15.0
IBM OS Image for Red Hat Linux Systems - update to 4.0.4.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5
Red Hat OpenShift Container Platform - addressed in versions 4.12.60, 4.13.45, 4.13.65, 4.14.31, 4.14.63, 4.15.19, 4.15.62, 4.16.0, 4.16.1, 4.16.58, 4.17.51, 4.18.35, 4.19.28
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.1.0
Storage Resource Manager - update to 5.0.1.0
Kube Descheduler Operator for Red Hat OpenShift - addressed in versions 5.0.2, 5.1.0
App Connect Enterprise Certified Container - addressed in versions 5.0.17, 11.5.0
IBM Tivoli Business Service Manager - update to 6.2.0.5.5
Dell EMC VxRail Appliance - update to 8.0.212
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.4
Storage Protect Server - update to 8.1.24
PowerScale OneFS - addressed in versions 9.4.0.19, 9.5.1.0, 9.5.1.1, 9.7.1.2, 9.9.0.0
IBM DB2 - addressed in versions 10.5 FP11, 11.1.4.7
IBM CICS TX Standard - update to 11.1.0.0 ifix40
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF004, 24.0.1-IF001
IBM Observability with Instana - update to 272
Integrated System for Microsoft Azure Stack Hub - update to 2606

External References

Related Security Bulletins