PT-2024-35091 · Hapi Fhir · Hapi Fhir

Dotasek

·

Published

2024-09-06

·

Updated

2024-11-12

·

CVE-2024-52007

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HAPI FHIR versions prior to 6.4.0
Description The XSLT parsing performed by various components in HAPI FHIR is vulnerable to XML external entity injections. This issue can be exploited by submitting a malicious XML file with a DTD tag, potentially allowing access to data from the host system. This vulnerability impacts use cases where org.hl7.fhir.core is being used within a host where external clients can submit XML. The estimated number of potentially affected devices is not specified.
Recommendations For versions prior to 6.4.0, upgrade to release version 6.4.0 to address the issue. As a temporary workaround, consider restricting access to the XSLT parsing components to minimize the risk of exploitation. Avoid using the org.hl7.fhir.core component in environments where external clients can submit XML until the issue is resolved. At the moment, there are no known workarounds for this vulnerability other than upgrading to the fixed version.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-52007
GHSA-6CR6-PH3P-F5RF
GHSA-GR3C-Q7XF-47VH

Affected Products

Hapi Fhir