Impact
XML parsing performed by the UcumEssenceService is vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag could produce XML containing data from the host system. This impacts use cases where ucum is being used to within a host where external clients can submit XML.
Patches
Release 1.0.9 of ucum fixes this vulnerability
Workarounds
Ensure that the source xml for instantiating UcumEssenceService is trusted.
References
Impact
XML parsing performed by the UcumEssenceService is vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag could produce XML containing data from the host system. This impacts use cases where ucum is being used to within a host where external clients can submit XML.
Patches
Release 1.0.9 of ucum fixes this vulnerability
Workarounds
Ensure that the source xml for instantiating UcumEssenceService is trusted.
References