PT-2026-26206 · Hapi Fhir · Hapi Fhir
Elliotsilver
·
Publicado
2026-03-18
·
Atualizado
2026-05-26
·
CVE-2026-33180
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HAPI FHIR versions prior to 6.9.0
Description
HAPI FHIR, a Java implementation of the HL7 FHIR standard, is affected by an issue where HTTP headers, potentially containing privacy-sensitive information, are sent to both the initial host and any subsequent hosts encountered during HTTP redirects. This occurs when the internal HTTP client follows redirects (30X HTTP response codes) and transmits the same headers to the host specified in the
Location response header. This could allow for impersonation of the client's request.Recommendations
Update to HAPI FHIR version 6.9.0 or later.
Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Hapi Fhir