Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependency Ucum-Java causes XXE vulnerability in XML parsing #6601

Open
mbialke opened this issue Jan 9, 2025 · 0 comments
Open

Dependency Ucum-Java causes XXE vulnerability in XML parsing #6601

mbialke opened this issue Jan 9, 2025 · 0 comments

Comments

@mbialke
Copy link

mbialke commented Jan 9, 2025

relates to HAPI FHIR Version 7.6.1

Ucum-java has an XXE vulnerability in XML parsing
CVE-2024-55887
Severity HIGH

Problem is fixed in Ucum-java v 1.0.9 , which is already available.

Update in pom.xml necessary.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant