{"id":"GHSA-68j8-fp38-p48q","summary":"Gematik Referenzvalidator has an XXE vulnerability that can lead to a Server Side Request Forgery attack","details":"### Impact\nThe profile location routine in the referencevalidator commons package is vulnerable to [XML External Entities](https://owasp.org/www-project-top-ten/2017/A4_2017-XML_External_Entities_(XXE)) attack due to insecure defaults of the used Woodstox WstxInputFactory. A malicious XML resource can lead to network requests issued by referencevalidator and thus to a [Server Side Request Forgery](https://owasp.org/www-community/attacks/Server_Side_Request_Forgery) attack.\n\nThe vulnerability impacts applications which use referencevalidator to process XML resources from untrusted sources. \n\n### Patches\nThe problem has been patched with the [2.5.1 version](https://github.com/gematik/app-referencevalidator/releases/tag/2.5.1) of the referencevalidator. Users are strongly recommended to update to this version or a more recent one. \n\n### Workarounds\nA pre-processing or manual analysis of input XML resources on existence of DTD definitions or external entities can mitigate the problem.\n\n### References\n- [OWASP Top 10 XXE](https://owasp.org/www-project-top-ten/2017/A4_2017-XML_External_Entities_(XXE)#)\n- [Server Side Request Forgery](https://owasp.org/www-community/attacks/Server_Side_Request_Forgery)\n- [OWASP XML External Entity Prevention Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html#transformerfactory)","aliases":["CVE-2024-46984"],"modified":"2024-09-20T15:01:12.039700Z","published":"2024-09-19T14:49:40Z","database_specific":{"nvd_published_at":"2024-09-19T23:15:12Z","cwe_ids":["CWE-611"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-09-19T14:49:40Z"},"references":[{"type":"WEB","url":"https://github.com/gematik/app-referencevalidator/security/advisories/GHSA-68j8-fp38-p48q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-46984"},{"type":"WEB","url":"https://github.com/gematik/app-referencevalidator/commit/d6d27613fab7a8dd08534946f29e0c51f319cad6"},{"type":"WEB","url":"https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html#transformerfactory"},{"type":"PACKAGE","url":"https://github.com/gematik/app-referencevalidator"},{"type":"WEB","url":"https://github.com/gematik/app-referencevalidator/releases/tag/2.5.1"},{"type":"WEB","url":"https://owasp.org/www-community/attacks/Server_Side_Request_Forgery"},{"type":"WEB","url":"https://owasp.org/www-project-top-ten/2017/A4_2017-XML_External_Entities_(XXE)"},{"type":"WEB","url":"https://owasp.org/www-project-top-ten/2017/A4_2017-XML_External_Entities_(XXE)#"}],"affected":[{"package":{"name":"de.gematik.refv.commons:commons","ecosystem":"Maven","purl":"pkg:maven/de.gematik.refv.commons/commons"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.1"}]}],"versions":["0.1.3","0.2.0","0.3.0","0.4.1","0.5.0","0.6.0","0.6.1","0.7.0","0.7.1","0.7.2","1.0.0","1.1.0","2.0.0","2.0.1","2.0.2","2.1.0","2.1.1","2.2.0","2.3.0","2.4.0","2.5.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-68j8-fp38-p48q/GHSA-68j8-fp38-p48q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N"}]}