Advisories for Maven/Org.fhir/Ucum package

2024

Ucum-java has an XXE vulnerability in XML parsing

XML parsing performed by the UcumEssenceService is vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag could produce XML containing data from the host system. This impacts use cases where ucum is being used to within a host where external clients can submit XML.