CVE-2024-55887
CVSS V2 None
CVSS V3 None
Description
Ucum-java is a FHIR Java library providing UCUM Services. In versions prior to 1.0.9, XML parsing performed by the UcumEssenceService is vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag could produce XML containing data from the host system. This impacts use cases where ucum is being used to within a host where external clients can submit XML. Release 1.0.9 of Ucum-java fixes this vulnerability. As a workaround, ensure that the source xml for instantiating UcumEssenceService is trusted.
Overview
- CVE ID
- CVE-2024-55887
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-12-13T16:08:55.658Z
- Last Modified Date
- 2024-12-13T17:06:54.775Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/FHIR/Ucum-java/security/advisories/GHSA-w9j7-phm3-f97j | x_refsource_CONFIRM |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-55887 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-55887 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-12-14 13:49:20 | Added to TrackCVE |