FHIR Core Artifacts Vulnerable to XML External Entity Injections
CVE-2024-45294

8.6HIGH

Key Information:

Vendor

Hapifhir

Vendor
CVE Published:
6 September 2024

What is CVE-2024-45294?

The HL7 FHIR Core Artifacts repository, which provides Java core object handling and utilities for the Fast Healthcare Interoperability Resources (FHIR) specification, is susceptible to XML external entity injections prior to version 6.3.23. This vulnerability can be exploited through the processing of specially crafted XML files containing malicious DTD tags, allowing attackers to extract sensitive data from the host system. This impacts any environment utilizing org.hl7.fhir.core where external clients can submit XML data. The issue has been resolved in release 6.3.23, and no alternatives or workarounds are currently available.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

org.hl7.fhir.core < 6.3.23

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.