Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6cr6-ph3p-f5rf

Опубликовано: 06 сент. 2024
Источник: github
Github: Прошло ревью
CVSS4: 7.7
CVSS3: 8.6

Описание

XXE vulnerability in XSLT transforms in org.hl7.fhir.core

Impact

XSLT transforms performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag ( <!DOCTYPE foo [<!ENTITY example SYSTEM "/etc/passwd"> ]> could produce XML containing data from the host system. This impacts use cases where org.hl7.fhir.core is being used to within a host where external clients can submit XML.

Patches

This issue has been patched in release 6.3.23

Workarounds

None.

References

MITRE CWE OWASP XML External Entity Prevention Cheat Sheet

Пакеты

Наименование

ca.uhn.hapi.fhir:org.hl7.fhir.dstu2016may

maven
Затронутые версииВерсия исправления

< 6.3.23

6.3.23

Наименование

ca.uhn.hapi.fhir:org.hl7.fhir.dstu3

maven
Затронутые версииВерсия исправления

< 6.3.23

6.3.23

Наименование

ca.uhn.hapi.fhir:org.hl7.fhir.r4

maven
Затронутые версииВерсия исправления

< 6.3.23

6.3.23

Наименование

ca.uhn.hapi.fhir:org.hl7.fhir.r4b

maven
Затронутые версииВерсия исправления

< 6.3.23

6.3.23

Наименование

ca.uhn.hapi.fhir:org.hl7.fhir.r5

maven
Затронутые версииВерсия исправления

< 6.3.23

6.3.23

Наименование

ca.uhn.hapi.fhir:org.hl7.fhir.utilities

maven
Затронутые версииВерсия исправления

< 6.3.23

6.3.23

EPSS

Процентиль: 21%
0.00066
Низкий

7.7 High

CVSS4

8.6 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 8.6
redhat
больше 1 года назад

The HL7 FHIR Core Artifacts repository provides the java core object handling code, with utilities (including validator), for the Fast Healthcare Interoperability Resources (FHIR) specification. Prior to version 6.3.23, XSLT transforms performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag could produce XML containing data from the host system. This impacts use cases where org.hl7.fhir.core is being used to within a host where external clients can submit XML. This issue has been patched in release 6.3.23. No known workarounds are available.

CVSS3: 8.6
nvd
больше 1 года назад

The HL7 FHIR Core Artifacts repository provides the java core object handling code, with utilities (including validator), for the Fast Healthcare Interoperability Resources (FHIR) specification. Prior to version 6.3.23, XSLT transforms performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag could produce XML containing data from the host system. This impacts use cases where org.hl7.fhir.core is being used to within a host where external clients can submit XML. This issue has been patched in release 6.3.23. No known workarounds are available.

EPSS

Процентиль: 21%
0.00066
Низкий

7.7 High

CVSS4

8.6 High

CVSS3

Дефекты

CWE-611