Описание
HAPI FHIR XML External Entity (XXE) vulnerability
An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.
Пакеты
ca.uhn.hapi.fhir:org.hl7.fhir.convertors
< 6.4.0
6.4.0
ca.uhn.hapi.fhir:org.hl7.fhir.dstu2
< 6.4.0
6.4.0
ca.uhn.hapi.fhir:org.hl7.fhir.dstu2016may
< 6.4.0
6.4.0
ca.uhn.hapi.fhir:org.hl7.fhir.dstu3
< 6.4.0
6.4.0
ca.uhn.hapi.fhir:org.hl7.fhir.r4
< 6.4.0
6.4.0
ca.uhn.hapi.fhir:org.hl7.fhir.r4b
< 6.4.0
6.4.0
ca.uhn.hapi.fhir:org.hl7.fhir.r5
< 6.4.0
6.4.0
ca.uhn.hapi.fhir:org.hl7.fhir.utilities
< 6.4.0
6.4.0
ca.uhn.hapi.fhir:org.hl7.fhir.validation
< 6.4.0
6.4.0
EPSS
8.8 High
CVSS4
9.8 Critical
CVSS3
CVE ID
Дефекты
Связанные уязвимости
An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.
An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.
EPSS
8.8 High
CVSS4
9.8 Critical
CVSS3