CVE-2024-55887

CVSS V2 None CVSS V3 None
Description
Ucum-java is a FHIR Java library providing UCUM Services. In versions prior to 1.0.9, XML parsing performed by the UcumEssenceService is vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag could produce XML containing data from the host system. This impacts use cases where ucum is being used to within a host where external clients can submit XML. Release 1.0.9 of Ucum-java fixes this vulnerability. As a workaround, ensure that the source xml for instantiating UcumEssenceService is trusted.
Overview
  • CVE ID
  • CVE-2024-55887
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-12-13T16:08:55.658Z
  • Last Modified Date
  • 2024-12-13T17:06:54.775Z
References
Reference URL Reference Tags
https://github.com/FHIR/Ucum-java/security/advisories/GHSA-w9j7-phm3-f97j x_refsource_CONFIRM
History
Created Old Value New Value Data Type Notes
2024-12-14 13:49:20 Added to TrackCVE