XML External Entity Injection in HL7 FHIR IG Publisher Tool
CVE-2024-52807
What is CVE-2024-52807?
The HL7 FHIR IG Publisher, a tool for generating compliant FHIR Implementation Guides, is vulnerable to XML External Entity (XXE) injections prior to version 1.7.4. Attackers can exploit this vulnerability by submitting XML with malicious DTD tags, potentially compromising sensitive data from the host system. This situation arises in scenarios where the publisher accepts XML inputs from external clients. The issue has been addressed in the latest version 1.7.4. Users are encouraged to update immediately, as no workarounds exist to mitigate the risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
fhir-ig-publisher < 1.7.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
