Impact
Bio-Formats up to 8.4.0 contains an XML External Entity (XXE) vulnerability. The issue is caused by an insecurely configured DocumentBuilderFactory that allows external entity resolution and external DTD loading when parsing user-supplied XML metadata.
Patches
Users should upgrade Bio-Formats to 8.5.0 or higher
Workarounds
There are no workaround
Attribution
Thanks to Beatriz Fresno Naumova who reported the issue.
References
Impact
Bio-Formats up to 8.4.0 contains an XML External Entity (XXE) vulnerability. The issue is caused by an insecurely configured DocumentBuilderFactory that allows external entity resolution and external DTD loading when parsing user-supplied XML metadata.
Patches
Users should upgrade Bio-Formats to 8.5.0 or higher
Workarounds
There are no workaround
Attribution
Thanks to Beatriz Fresno Naumova who reported the issue.
References