PT-2024-32318 · Unknown · Referencevalidator+1

Alexey-Tschudnowsky

·

Published

2024-09-19

·

Updated

2024-09-25

·

CVE-2024-46984

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions referencevalidator versions prior to 2.5.1
Description The profile location routine in the referencevalidator commons package is vulnerable to XML External Entities attack due to insecure defaults of the used Woodstox WstxInputFactory. A malicious XML resource can lead to network requests issued by referencevalidator and thus to a Server Side Request Forgery attack. The vulnerability impacts applications which use referencevalidator to process XML resources from untrusted sources.
Recommendations For versions prior to 2.5.1, update to version 2.5.1 or a more recent one to resolve the issue. As a temporary workaround, consider pre-processing or manual analysis of input XML resources for existence of DTD definitions or external entities to mitigate the problem.

Exploit

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2024-46984
GHSA-68J8-FP38-P48Q

Affected Products

Woodstox Wstxinputfactory
Referencevalidator