Junglewise Threat Intelligence

CVE-2024-34393: libxmljs2 type confusion vulnerability in XML parsing

CVE-2024-34393 · Severity: low · CVSS 3.1 · Published 2024-05-02

Vendors: npm.

Executive brief

libxmljs2 is a JavaScript library used to parse and manipulate XML documents in Node.js applications. A type confusion vulnerability when parsing specially crafted XML can allow an attacker to crash the application, leak sensitive data, cause infinite loops, or potentially execute arbitrary code on 32-bit systems. Applications using this library to process untrusted XML input are at risk.

Technical details

The vulnerability is a type confusion issue (CWE-843) triggered when parsing a specially crafted XML document and invoking a function on the result of the attrs() method called on a parsed node. The flaw affects all versions through 0.33.0 with no patch available at the time of publication. The attack requires network reachability and specially crafted XML input (no authentication required). Depending on the system architecture and compilation flags, an attacker can achieve denial of service, information disclosure, infinite loops, or remote code execution on 32-bit systems with XML_PARSE_HUGE enabled.

Affected products

  • libxmljs2 libxmljs2 0.33.0 and earlier

Timeline

  • 2024-05-02: disclosed
  • 2024-05-03: advisory

References

Related threats