Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-45294

Опубликовано: 06 сент. 2024
Источник: redhat
CVSS3: 8.6
EPSS Низкий

Описание

The HL7 FHIR Core Artifacts repository provides the java core object handling code, with utilities (including validator), for the Fast Healthcare Interoperability Resources (FHIR) specification. Prior to version 6.3.23, XSLT transforms performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag could produce XML containing data from the host system. This impacts use cases where org.hl7.fhir.core is being used to within a host where external clients can submit XML. This issue has been patched in release 6.3.23. No known workarounds are available.

A flaw was found in HAPI FHIR - HL7 FHIR Core Artifacts. eXtensible Stylesheet Language Transformations (XSLT) transforms performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag could produce XML containing data from the host system. This issue impacts use cases where org.hl7.fhir.core is being used within a host where external clients can submit XML.

Отчет

This vulnerability is of significant severity because it allows for XML External Entity (XXE) injection, which can lead to unauthorized access and leakage of sensitive data from the host system. In environments where external clients are permitted to submit XML files, an attacker could craft a malicious XML containing a DTD (Document Type Definition) that references external entities. When processed, this could result in the unauthorized disclosure of files, environmental variables, or other confidential data from the server, potentially compromising the integrity and confidentiality of the system.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 3ca.uhn.hapi.fhir/org.hl7.fhir.dstu2016mayAffected
Red Hat build of Apache Camel for Spring Boot 3ca.uhn.hapi.fhir/org.hl7.fhir.dstu3Affected
Red Hat build of Apache Camel for Spring Boot 3ca.uhn.hapi.fhir/org.hl7.fhir.r4Affected
Red Hat build of Apache Camel for Spring Boot 3ca.uhn.hapi.fhir/org.hl7.fhir.r5Affected
Red Hat build of Apache Camel for Spring Boot 3ca.uhn.hapi.fhir/org.hl7.fhir.utilitiesAffected
Red Hat build of Quarkusca.uhn.hapi.fhir/org.hl7.fhir.dstu2016mayNot affected
Red Hat build of Quarkusca.uhn.hapi.fhir/org.hl7.fhir.dstu3Not affected
Red Hat build of Quarkusca.uhn.hapi.fhir/org.hl7.fhir.r4Not affected
Red Hat build of Quarkusca.uhn.hapi.fhir/org.hl7.fhir.r5Not affected
Red Hat build of Quarkusca.uhn.hapi.fhir/org.hl7.fhir.utilitiesNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=2310447org.hl7.fhir.core: org.hl7.fhir.dstu3: org.hl7.fhir.r4: org.hl7.fhir.r4b: org.hl7.fhir.r5: org.hl7.fhir.utilities: XXE vulnerability in XSLT transforms in `org.hl7.fhir.core`

EPSS

Процентиль: 21%
0.00066
Низкий

8.6 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
nvd
больше 1 года назад

The HL7 FHIR Core Artifacts repository provides the java core object handling code, with utilities (including validator), for the Fast Healthcare Interoperability Resources (FHIR) specification. Prior to version 6.3.23, XSLT transforms performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag could produce XML containing data from the host system. This impacts use cases where org.hl7.fhir.core is being used to within a host where external clients can submit XML. This issue has been patched in release 6.3.23. No known workarounds are available.

CVSS3: 8.6
github
больше 1 года назад

XXE vulnerability in XSLT transforms in `org.hl7.fhir.core`

EPSS

Процентиль: 21%
0.00066
Низкий

8.6 High

CVSS3