PT-2024-34533 · Hapi Fhir · Hapi Fhir
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
HAPI FHIR versions prior to 6.4.0
Description:
The issue allows attackers to access sensitive information or execute arbitrary code by supplying a crafted request containing malicious XML entities. This is due to an XML External Entity (XXE) vulnerability.
Recommendations:
For versions prior to 6.4.0, update to version 6.4.0 or later to resolve the issue. As a temporary workaround, consider restricting the processing of external XML entities to minimize the risk of exploitation.
Exploit
Fix
Open Redirect
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hapi Fhir