Vulnerability record · CVE-2024-23807 · published 29 February 2024
CVE-2024-23807: Apache xerces-c\+\+ use after free vulnerability
Apache · Xerces C\+\+
The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. Users are recommended to upgrade to version 3.2.5 which fixes the issue, or mitigate the issue by disabling DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable. This issue has been disclosed before as CVE-2018-1311, but unfortunately that advisory incorrectly stated the issue would be fixed in version 3.2.3 or 3.2.4.
Description
The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. Users are recommended to upgrade to version 3.2.5 which fixes the issue, or mitigate the issue by disabling DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable. This issue has been disclosed before as CVE-2018-1311, but unfortunately that advisory incorrectly stated the issue would be fixed in version 3.2.3 or 3.2.4.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/apache/xerces-c/pull/54 | ExploitPatchThird Party Advisory |
| https://lists.apache.org/thread/c497tgn864tsbm8w0bo3f0d81s07zk9r | Mailing ListPatchVendor Advisory |
| https://github.com/apache/xerces-c/pull/54 | ExploitPatchThird Party Advisory |
| https://lists.apache.org/thread/c497tgn864tsbm8w0bo3f0d81s07zk9r | Mailing ListPatchVendor Advisory |
Track CVE-2024-23807 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-23807), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.