Advisories for Maven/De.gematik.refv.commons/Commons package

2024

Gematik Referenzvalidator has an XXE vulnerability that can lead to a Server Side Request Forgery attack

The profile location routine in the referencevalidator commons package is vulnerable to XML External Entities attack due to insecure defaults of the used Woodstox WstxInputFactory. A malicious XML resource can lead to network requests issued by referencevalidator and thus to a Server Side Request Forgery attack. The vulnerability impacts applications which use referencevalidator to process XML resources from untrusted sources.