{"id":"CVE-2024-46984","aliases":["GHSA-68j8-fp38-p48q"],"url":"https://o3.security/vulnerability/CVE-2024-46984","summary":"XML External Entity Reference (XXE) vulnerability can lead to a Server Side Request Forgery attack in gematik app-referencevalidator","details":"### Impact\nThe profile location routine in the referencevalidator commons package is vulnerable to [XML External Entities](https://owasp.org/www-project-top-ten/2017/A4_2017-XML_External_Entities_(XXE)) attack due to insecure defaults of the used Woodstox WstxInputFactory. A malicious XML resource can lead to network requests issued by referencevalidator and thus to a [Server Side Request Forgery](https://owasp.org/www-community/attacks/Server_Side_Request_Forgery) attack.\n\nThe vulnerability impacts applications which use referencevalidator to process XML resources from untrusted sources. \n\n### Patches\nThe problem has been patched with the [2.5.1 version](https://github.com/gematik/app-referencevalidator/releases/tag/2.5.1) of the referencevalidator. Users are strongly recommended to update to this version or a more recent one. \n\n### Workarounds\nA pre-processing or manual analysis of input XML resources on existence of DTD definitions or external entities can mitigate the problem.\n\n### References\n- [OWASP Top 10 XXE](https://owasp.org/www-project-top-ten/2017/A4_2017-XML_External_Entities_(XXE)#)\n- [Server Side Request Forgery](https://owasp.org/www-community/attacks/Server_Side_Request_Forgery)\n- [OWASP XML External Entity Prevention Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html#transformerfactory)","published":"2024-09-19T22:38:21.169Z","modified":"2026-08-12T03:51:41.718535639Z","cvss":{"score":8.6,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"},"epss":{"score":0.00637,"percentile":0.47643,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"de.gematik.refv.commons:commons","fixedVersion":"2.5.1"}],"fix":{"url":"https://github.com/gematik/app-referencevalidator/commit/d6d27613fab7a8dd08534946f29e0c51f319cad6","label":"gematik/app-referencevalidator@d6d2761"},"references":[{"type":"WEB","url":"https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html#transformerfactory"},{"type":"WEB","url":"https://github.com/gematik/app-referencevalidator/releases/tag/2.5.1"},{"type":"WEB","url":"https://owasp.org/www-community/attacks/Server_Side_Request_Forgery"},{"type":"WEB","url":"https://owasp.org/www-project-top-ten/2017/A4_2017-XML_External_Entities_(XXE)"},{"type":"WEB","url":"https://owasp.org/www-project-top-ten/2017/A4_2017-XML_External_Entities_(XXE)#"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/46xxx/CVE-2024-46984.json"},{"type":"ADVISORY","url":"https://github.com/gematik/app-referencevalidator/security/advisories/GHSA-68j8-fp38-p48q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-46984"},{"type":"WEB","url":"https://github.com/gematik/app-referencevalidator/commit/d6d27613fab7a8dd08534946f29e0c51f319cad6"},{"type":"PACKAGE","url":"https://github.com/gematik/app-referencevalidator"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:41.718535639Z"}}