In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.
The SAX parser in libxml2 generates events for external XML entities even when custom SAX handlers attempt to override entity content by setting the 'checked' flag. This mechanism should block processing of external entities, however a bug in the implementation causes the flag to be ignored. As a result, an attacker can deliver a crafted XML document containing references to external entities that will be processed by the parser despite application security measures.
An attacker can manipulate XML document processing in a way that violates data integrity or causes application unavailability (denial of service). Classic XXE attacks are possible, including reading system files or forcing server-side requests (SSRF), depending on the application context.
Update libxml2 to version 2.11.9, 2.12.9, or 2.13.3 (according to the branch in use). NetApp product users should follow the manufacturer's recommendations available at https://security.netapp.com/advisory/ntap-20250228-0004/. Additionally, it is recommended to verify that applications using libxml2 do not rely solely on custom SAX handlers as the only protection mechanism against XXE.
libxml2 in versions: 2.11.x before 2.11.9, 2.12.x before 2.12.9, and 2.13.x before 2.13.3. Also affects NetApp HCI Compute Node and NetApp SolidFire & HCI Management Node products based on vulnerable library versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HNetapp H300s
HWNetappall versionsNetapp H300s Firmware
OSNetappall versionsNetapp H410c
HWNetappall versionsNetapp H410c Firmware
OSNetappall versionsNetapp H410s
HWNetappall versionsNetapp H410s Firmware
OSNetappall versionsNetapp H500s
HWNetappall versionsNetapp H500s Firmware
OSNetappall versionsNetapp H700s
HWNetappall versionsNetapp H700s Firmware
OSNetappall versionsNetapp Hci Compute Node
OSNetappall versionsNetapp Solidfire \& Hci Management Node
APPNetappall versionsNetapp Solidfire \& Hci Storage Node
APPNetappall versionsXmlsoft Libxml2
APPXmlsoft2.11.0 – 2.11.9 (excl.)2.13.0 – 2.13.3 (excl.)2.12.0 – 2.12.9 (excl.)
Related vulnerabilities
AMI MegaRAC SPx — zdalne ominięcie uwierzytelnienia w interfejsie Redfish BMC
Apache Tomcat: Path Equivalence prowadzący do RCE i ujawnienia danych
Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup
Apache Tomcat: niekompletna mitygacja TOCTOU Race Condition (CVE-2024-50379)
RCE via TOCTOU Race Condition podczas kompilacji JSP w Apache Tomcat