FixVibe

critical

Critical XXE Vulnerability in http4k-format-xml (CVE-2024-55875)

The http4k-format-xml library is vulnerable to XML External Entity (XXE) injection. Attackers can exploit this by sending malicious XML payloads to applications using affected versions of the library, potentially leading to sensitive information disclosure, Server-Side Request Forgery (SSRF), and denial of service.

CVE-2024-55875GHSA-7mj5-hjjj-8rgwCWE-611

Impact

An attacker can exploit this vulnerability to read sensitive files from the server's filesystem, access internal network resources via Server-Side Request Forgery (SSRF), or cause a denial of service [S2]. This vulnerability affects applications that process XML input using the http4k-format-xml module [S3].

Root Cause

The org.http4k:http4k-format-xml library, in versions prior to 6.50.0.0, does not sufficiently restrict the processing of external entities within XML documents [S2]. When the library parses XML input from an untrusted source, it may attempt to resolve external references defined in the Document Type Definition (DTD), allowing an attacker to point the parser to local files or internal URLs [S3]. This behavior is identified as CVE-2024-55875 [S1].

Concrete Fixes

Update the http4k-format-xml dependency to version 6.50.0.0 or later [S2]. This version addresses the vulnerability by ensuring the underlying XML parser is configured to prevent external entity resolution [S3].

Covered by FixVibe

FixVibe's GitHub repo scans flag Maven or Gradle build files that resolve org.http4k:http4k-format-xml below 6.50.0.0, with the patched version to upgrade to.