{"id":"GHSA-w9j7-phm3-f97j","summary":"Ucum-java has an XXE vulnerability in XML parsing","details":"### Impact\nXML parsing performed by the UcumEssenceService is vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag could produce XML containing data from the host system. This impacts use cases where ucum is being used to within a host where external clients can submit XML.\n\n### Patches\nRelease 1.0.9 of ucum fixes this vulnerability\n\n### Workarounds\nEnsure that the source xml for instantiating UcumEssenceService is trusted.\n\n### References\n* https://cwe.mitre.org/data/definitions/611.html\n* https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html#jaxp-documentbuilderfactory-saxparserfactory-and-dom4j\n","aliases":["CVE-2024-55887"],"modified":"2024-12-13T21:12:11.218160Z","published":"2024-12-13T20:35:57Z","database_specific":{"github_reviewed_at":"2024-12-13T20:35:57Z","nvd_published_at":"2024-12-13T16:15:28Z","cwe_ids":["CWE-611"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/FHIR/Ucum-java/security/advisories/GHSA-w9j7-phm3-f97j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-55887"},{"type":"PACKAGE","url":"https://github.com/FHIR/Ucum-java"}],"affected":[{"package":{"name":"org.fhir:ucum","ecosystem":"Maven","purl":"pkg:maven/org.fhir/ucum"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.9"}]}],"versions":["1.0","1.0.1","1.0.2","1.0.3","1.0.6","1.0.7","1.0.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-w9j7-phm3-f97j/GHSA-w9j7-phm3-f97j.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"}]}