PT-2019-12911 · Hapi · Hapi Fhir Library
Published
2019-06-05
·
Updated
2019-06-07
·
CVE-2019-12741
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
HAPI FHIR library versions prior to 3.8.0
Description
The issue involves unsanitized HTTP parameters being output in a form page, allowing attackers to leak cookies and other sensitive information via a specially crafted URL, specifically targeting the
ca/uhn/fhir/to/BaseController.java file. The attack surface is expected to be low since the affected module is not generally used in production systems.Recommendations
For versions prior to 3.8.0, upgrade to version 3.8.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the HAPI FHIR testpage overlay module until the upgrade is applied.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hapi Fhir Library