Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-51132

Опубликовано: 05 нояб. 2024
Источник: redhat
CVSS3: 9.1
EPSS Низкий

Описание

An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.

A flaw was found in Fast Healthcare Interoperability Resources (HAPI FHIR). This vulnerability could allow attackers to execute arbitrary code or access sensitive information via a crafted request which contains malicious XML entities.

Отчет

Red Hat Build of Apache Camel K provides support for a select group of extensions for Camel Quarkus. As FHIR is not on this list, it is marked as out of support scope. Consult the external references section for the list of supported Camel Quarkus extension. While Red Hat Fuse 7 includes a vulnerable version of FHIR, the product does not utilize the affected function. This reduces impact of the vulnerability to Low.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 3ca.uhn.hapi.fhir/org.hl7.fhir.dstu2Out of support scope
Red Hat build of Apache Camel for Spring Boot 3ca.uhn.hapi.fhir/org.hl7.fhir.dstu2016mayOut of support scope
Red Hat build of Apache Camel for Spring Boot 3ca.uhn.hapi.fhir/org.hl7.fhir.dstu3Out of support scope
Red Hat build of Apache Camel for Spring Boot 3ca.uhn.hapi.fhir/org.hl7.fhir.r4Out of support scope
Red Hat build of Apache Camel for Spring Boot 3ca.uhn.hapi.fhir/org.hl7.fhir.r5Out of support scope
Red Hat build of Apache Camel for Spring Boot 3ca.uhn.hapi.fhir/org.hl7.fhir.utilitiesOut of support scope
Red Hat Fuse 7ca.uhn.hapi.fhir/org.hl7.fhir.convertorsFix deferred
Red Hat Fuse 7ca.uhn.hapi.fhir-org.hl7.fhir.coreFix deferred
Red Hat Fuse 7ca.uhn.hapi.fhir/org.hl7.fhir.dstu2Fix deferred
Red Hat Fuse 7ca.uhn.hapi.fhir/org.hl7.fhir.dstu2016mayFix deferred

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-611->CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2323897org.hl7.fhir.convertors: org.hl7.fhir.dstu2: org.hl7.fhir.dstu2016may: org.hl7.fhir.dstu3: org.hl7.fhir.r4: org.hl7.fhir.r5: org.hl7.fhir.utilities: org.hl7.fhir.validation: org.hl7.fhir.core: FHIR arbitrary code execution via specially-crafted request

EPSS

Процентиль: 90%
0.06005
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
около 1 года назад

An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.

CVSS3: 9.8
github
около 1 года назад

HAPI FHIR XML External Entity (XXE) vulnerability

EPSS

Процентиль: 90%
0.06005
Низкий

9.1 Critical

CVSS3