PT-2019-12911 · Hapi · Hapi Fhir Library

Published

2019-06-05

·

Updated

2019-06-07

·

CVE-2019-12741

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions HAPI FHIR library versions prior to 3.8.0
Description The issue involves unsanitized HTTP parameters being output in a form page, allowing attackers to leak cookies and other sensitive information via a specially crafted URL, specifically targeting the ca/uhn/fhir/to/BaseController.java file. The attack surface is expected to be low since the affected module is not generally used in production systems.
Recommendations For versions prior to 3.8.0, upgrade to version 3.8.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the HAPI FHIR testpage overlay module until the upgrade is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-12741
GHSA-52MH-P2M2-W625

Affected Products

Hapi Fhir Library