PT-2024-31547 · Unknown · Hl7 Fhir Core Artifacts
Qligier
·
Published
2024-09-06
·
Updated
2024-09-06
·
CVE-2024-45294
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HL7 FHIR Core Artifacts repository versions prior to 6.3.23
Description
The issue concerns XML external entity injections in XSLT transforms performed by various components. A processed XML file with a malicious DTD tag could produce XML containing data from the host system, impacting use cases where external clients can submit XML. This affects scenarios where the repository is used within a host that allows external client XML submissions.
Recommendations
For versions prior to 6.3.23, update to release 6.3.23 to resolve the issue. As a temporary workaround, consider restricting the submission of XML files from external clients until the update is applied. Avoid using the
<!DOCTYPE> tag with external entities in XML files until the issue is resolved. At the moment, there are no other known workarounds available.Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hl7 Fhir Core Artifacts