Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-51132

Опубликовано: 05 нояб. 2024
Источник: redhat
CVSS3: 9.1
EPSS Низкий

Описание

An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.

A flaw was found in Fast Healthcare Interoperability Resources (HAPI FHIR). This vulnerability could allow attackers to execute arbitrary code or access sensitive information via a crafted request which contains malicious XML entities.

Отчет

Red Hat Build of Apache Camel K provides support for a select group of extensions for Camel Quarkus. As FHIR is not on this list, it is marked as out of support scope. Consult the external references section for the list of supported Camel Quarkus extension. While Red Hat Fuse 7 includes a vulnerable version of FHIR, the product does not utilize the affected function. This reduces impact of the vulnerability to Low.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 3org.hl7.fhir.dstu2Out of support scope
Red Hat build of Apache Camel for Spring Boot 3org.hl7.fhir.dstu2016mayOut of support scope
Red Hat build of Apache Camel for Spring Boot 3org.hl7.fhir.dstu3Out of support scope
Red Hat build of Apache Camel for Spring Boot 3org.hl7.fhir.r4Out of support scope
Red Hat build of Apache Camel for Spring Boot 3org.hl7.fhir.r5Out of support scope
Red Hat build of Apache Camel for Spring Boot 3org.hl7.fhir.utilitiesOut of support scope
Red Hat Fuse 7ca.uhn.hapi.fhir/org.hl7.fhir.convertorsFix deferred
Red Hat Fuse 7ca.uhn.hapi.fhir-org.hl7.fhir.coreFix deferred
Red Hat Fuse 7ca.uhn.hapi.fhir/org.hl7.fhir.validationFix deferred
Red Hat Fuse 7ca.uhn.hapi.fhir/org.hl7.fhir.validation.cliFix deferred

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=2323897org.hl7.fhir.convertors: org.hl7.fhir.dstu2: org.hl7.fhir.dstu2016may: org.hl7.fhir.dstu3: org.hl7.fhir.r4: org.hl7.fhir.r5: org.hl7.fhir.utilities: org.hl7.fhir.validation: org.hl7.fhir.core: FHIR arbitrary code execution via specially-crafted request

EPSS

Процентиль: 78%
0.01904
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
почти 2 года назад

An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.

CVSS3: 9.8
github
почти 2 года назад

HAPI FHIR XML External Entity (XXE) vulnerability

EPSS

Процентиль: 78%
0.01904
Низкий

9.1 Critical

CVSS3