Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3518 | Ucum-java is a FHIR Java library providing UCUM Services. In versions prior to 1.0.9, XML parsing performed by the UcumEssenceService is vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag could produce XML containing data from the host system. This impacts use cases where ucum is being used to within a host where external clients can submit XML. Release 1.0.9 of Ucum-java fixes this vulnerability. As a workaround, ensure that the source xml for instantiating UcumEssenceService is trusted. |
Github GHSA |
GHSA-w9j7-phm3-f97j | Ucum-java has an XXE vulnerability in XML parsing |
Sat, 14 Dec 2024 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 13 Dec 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Ucum-java has an XXE vulnerability in XML parsing | |
| Metrics |
ssvc
|
Fri, 13 Dec 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ucum-java is a FHIR Java library providing UCUM Services. In versions prior to 1.0.9, XML parsing performed by the UcumEssenceService is vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag could produce XML containing data from the host system. This impacts use cases where ucum is being used to within a host where external clients can submit XML. Release 1.0.9 of Ucum-java fixes this vulnerability. As a workaround, ensure that the source xml for instantiating UcumEssenceService is trusted. | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-12-13T17:06:54.775Z
Reserved: 2024-12-12T15:00:38.902Z
Link: CVE-2024-55887
Updated: 2024-12-13T17:06:41.806Z
Status : Deferred
Published: 2024-12-13T16:15:28.063
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-55887
OpenCVE Enrichment
No data.
EUVD
Github GHSA