CVE Vulnerabilities

CVE-2021-3541

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

Published: Jul 09, 2021 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service.

Weakness

The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.

Affected Software

NameVendorStart VersionEnd Version
Libxml2Xmlsoft*2.9.11 (excluding)
JBoss Core Services for RHEL 8RedHatjbcs-httpd24-apr-util-0:1.6.1-91.el8jbcs*
JBoss Core Services for RHEL 8RedHatjbcs-httpd24-curl-0:7.78.0-3.el8jbcs*
JBoss Core Services for RHEL 8RedHatjbcs-httpd24-httpd-0:2.4.37-80.el8jbcs*
JBoss Core Services for RHEL 8RedHatjbcs-httpd24-mod_cluster-native-0:1.3.16-10.Final_redhat_2.el8jbcs*
JBoss Core Services for RHEL 8RedHatjbcs-httpd24-mod_http2-0:1.15.7-22.el8jbcs*
JBoss Core Services for RHEL 8RedHatjbcs-httpd24-mod_jk-0:1.2.48-29.redhat_1.el8jbcs*
JBoss Core Services for RHEL 8RedHatjbcs-httpd24-mod_md-1:2.0.8-41.el8jbcs*
JBoss Core Services for RHEL 8RedHatjbcs-httpd24-mod_security-0:2.9.2-68.GA.el8jbcs*
JBoss Core Services for RHEL 8RedHatjbcs-httpd24-nghttp2-0:1.39.2-41.el8jbcs*
JBoss Core Services for RHEL 8RedHatjbcs-httpd24-openssl-1:1.1.1g-11.el8jbcs*
JBoss Core Services for RHEL 8RedHatjbcs-httpd24-openssl-chil-0:1.0.0-11.el8jbcs*
JBoss Core Services for RHEL 8RedHatjbcs-httpd24-openssl-pkcs11-0:0.4.10-26.el8jbcs*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-apr-util-0:1.6.1-91.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-curl-0:7.78.0-3.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-httpd-0:2.4.37-80.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-mod_cluster-native-0:1.3.16-10.Final_redhat_2.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-mod_http2-0:1.15.7-22.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-mod_jk-0:1.2.48-29.redhat_1.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-mod_md-1:2.0.8-41.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-mod_security-0:2.9.2-68.GA.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-nghttp2-0:1.39.2-41.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-openssl-1:1.1.1g-11.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-openssl-chil-0:1.0.0-11.jbcs.el7*
JBoss Core Services on RHEL 7RedHatjbcs-httpd24-openssl-pkcs11-0:0.4.10-26.jbcs.el7*
Red Hat Enterprise Linux 8RedHatlibxml2-0:2.9.7-9.el8_4.2*
Red Hat Enterprise Linux 8RedHatlibxml2-0:2.9.7-9.el8_4.2*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-controller-rhel8:v1.4.6-4*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-log-reader-rhel8:v1.4.6-4*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-must-gather-rhel8:v1.4.6-4*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-operator-bundle:v1.4.6-5*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-registry-rhel8:v1.4.6-4*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-rsync-transfer-rhel8:v1.4.6-4*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-ui-rhel8:v1.4.6-4*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-velero-plugin-for-aws-rhel8:v1.4.6-4*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-velero-plugin-for-gcp-rhel8:v1.4.6-3*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-velero-plugin-for-microsoft-azure-rhel8:v1.4.6-4*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-velero-restic-restore-helper-rhel8:v1.4.6-5*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-migration-velero-rhel8:v1.4.6-5*
Red Hat Migration Toolkit for Containers 1.4RedHatrhmtc/openshift-velero-plugin-rhel8:v1.4.6-4*
Text-Only JBCSRedHatlibxml2*
Libxml2Ubuntuesm-infra/focal*
Libxml2Ubuntufocal*
Libxml2Ubuntugroovy*
Libxml2Ubuntuhirsute*
Libxml2Ubuntuprecise/esm*
Libxml2Ubuntutrusty*
Libxml2Ubuntuupstream*
Libxml2Ubuntuxenial*

Potential Mitigations

References