XML External Entity (XXE) Injection Affecting expat-devel package, versions <0:2.2.5-15.el8_10
Threat Intelligence
EPSS
0.05% (19th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-ROCKY8-EXPATDEVEL-8134638
- published 1 Oct 2024
- disclosed 30 Aug 2024
Introduced: 30 Aug 2024
CVE-2024-45490 Open this link in a new tabHow to fix?
Upgrade Rocky-Linux:8
expat-devel
to version 0:2.2.5-15.el8_10 or higher.
This issue was patched in RLSA-2024:6989
.
NVD Description
Note: Versions mentioned in the description apply only to the upstream expat-devel
package and not the expat-devel
package as distributed by Rocky-Linux
.
See How to fix?
for Rocky-Linux:8
relevant fixed versions and status.
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
CVSS Scores
version 3.1