Impact
An attacker can exploit this vulnerability to read sensitive files from the server's filesystem, access internal network resources via Server-Side Request Forgery (SSRF), or cause a denial of service [S2]. This vulnerability affects applications that process XML input using the http4k-format-xml module [S3].
Root Cause
The org.http4k:http4k-format-xml library, in versions prior to 6.50.0.0, does not sufficiently restrict the processing of external entities within XML documents [S2]. When the library parses XML input from an untrusted source, it may attempt to resolve external references defined in the Document Type Definition (DTD), allowing an attacker to point the parser to local files or internal URLs [S3]. This behavior is identified as CVE-2024-55875 [S1].
Concrete Fixes
Update the http4k-format-xml dependency to version 6.50.0.0 or later [S2]. This version addresses the vulnerability by ensuring the underlying XML parser is configured to prevent external entity resolution [S3].
Covered by FixVibe
FixVibe's GitHub repo scans flag Maven or Gradle build files that resolve org.http4k:http4k-format-xml below 6.50.0.0, with the patched version to upgrade to.
