org.hl7.fhir.convertors: org.hl7.fhir.dstu2: org.hl7.fhir.dstu2016may: org.hl7.fhir.dstu3: org.hl7.fhir.r4: org.hl7.fhir.r5: org.hl7.fhir.utilities: org.hl7.fhir.validation: org.hl7.fhir.core: FHIR arbitrary code execution via specially-crafted request
Published Nov 5, 2024
8.8
HIGHCVSS 4.0
EPSS 1.90%
Description
An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.
Affected products
No data.
No data.
-
- Version 0StatusaffectedConstraints<6.4.0
- Version
Red Hat Build of Apache Camel 4.4 for Quarkus 3.8
ca.uhn.hapi.fhir-org.hl7.fhir.utilities
Fixed · RHSA-2024:10035
Red Hat Build of Apache Camel 4.4 for Quarkus 3.8
org.hl7.fhir.dstu2
Fixed · RHSA-2024:10035
Red Hat Build of Apache Camel 4.4 for Quarkus 3.8
org.hl7.fhir.dstu2016may
Fixed · RHSA-2024:10035
Red Hat Build of Apache Camel 4.4 for Quarkus 3.8
org.hl7.fhir.dstu3
Fixed · RHSA-2024:10035
Red Hat Build of Apache Camel 4.4 for Quarkus 3.8
org.hl7.fhir.r4
Fixed · RHSA-2024:10035
Red Hat Build of Apache Camel 4.4 for Quarkus 3.8
org.hl7.fhir.r5
Fixed · RHSA-2024:10035
Red Hat build of Apache Camel 4.4.4 for Spring Boot
org.hl7.fhir.dstu2
Fixed · RHSA-2024:9806
Red Hat build of Apache Camel 4.4.4 for Spring Boot
org.hl7.fhir.dstu2016may
Fixed · RHSA-2024:9806
Red Hat build of Apache Camel 4.4.4 for Spring Boot
org.hl7.fhir.dstu3
Fixed · RHSA-2024:9806
Red Hat build of Apache Camel 4.4.4 for Spring Boot
org.hl7.fhir.r4
Fixed · RHSA-2024:9806
Red Hat build of Apache Camel 4.4.4 for Spring Boot
org.hl7.fhir.r5
Fixed · RHSA-2024:9806
Red Hat build of Apache Camel 4.4.4 for Spring Boot
org.hl7.fhir.utilities
Fixed · RHSA-2024:9806
Red Hat Fuse 7
ca.uhn.hapi.fhir-org.hl7.fhir.core
Fix deferred
Red Hat Fuse 7
ca.uhn.hapi.fhir/org.hl7.fhir.convertors
Fix deferred
Red Hat Fuse 7
ca.uhn.hapi.fhir/org.hl7.fhir.validation
Fix deferred
Red Hat Fuse 7
ca.uhn.hapi.fhir/org.hl7.fhir.validation.cli
Fix deferred
Red Hat Fuse 7
org.hl7.fhir.dstu2
Fix deferred
Red Hat Fuse 7
org.hl7.fhir.dstu2016may
Fix deferred
Red Hat Fuse 7
org.hl7.fhir.dstu3
Fix deferred
Red Hat Fuse 7
org.hl7.fhir.r4
Fix deferred
Red Hat Fuse 7
org.hl7.fhir.r5
Fix deferred
Red Hat Fuse 7
org.hl7.fhir.utilities
Fix deferred
Red Hat Integration Camel K 1
org.hl7.fhir.dstu3
Out of support scope
Red Hat Integration Camel K 1
org.hl7.fhir.r4
Out of support scope
Red Hat Integration Camel K 1
org.hl7.fhir.r5
Out of support scope
Red Hat Integration Camel K 1
org.hl7.fhir.utilities
Out of support scope
Red Hat build of Apache Camel for Spring Boot 3
org.hl7.fhir.dstu2
Out of support scope
Red Hat build of Apache Camel for Spring Boot 3
org.hl7.fhir.dstu2016may
Out of support scope
Red Hat build of Apache Camel for Spring Boot 3
org.hl7.fhir.dstu3
Out of support scope
Red Hat build of Apache Camel for Spring Boot 3
org.hl7.fhir.r4
Out of support scope
Red Hat build of Apache Camel for Spring Boot 3
org.hl7.fhir.r5
Out of support scope
Red Hat build of Apache Camel for Spring Boot 3
org.hl7.fhir.utilities
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Build of Apache Camel 4.4 for Quarkus 3.8 | ca.uhn.hapi.fhir-org.hl7.fhir.utilities | Fixed | RHSA-2024:10035 |
| Red Hat Build of Apache Camel 4.4 for Quarkus 3.8 | org.hl7.fhir.dstu2 | Fixed | RHSA-2024:10035 |
| Red Hat Build of Apache Camel 4.4 for Quarkus 3.8 | org.hl7.fhir.dstu2016may | Fixed | RHSA-2024:10035 |
| Red Hat Build of Apache Camel 4.4 for Quarkus 3.8 | org.hl7.fhir.dstu3 | Fixed | RHSA-2024:10035 |
| Red Hat Build of Apache Camel 4.4 for Quarkus 3.8 | org.hl7.fhir.r4 | Fixed | RHSA-2024:10035 |
| Red Hat Build of Apache Camel 4.4 for Quarkus 3.8 | org.hl7.fhir.r5 | Fixed | RHSA-2024:10035 |
| Red Hat build of Apache Camel 4.4.4 for Spring Boot | org.hl7.fhir.dstu2 | Fixed | RHSA-2024:9806 |
| Red Hat build of Apache Camel 4.4.4 for Spring Boot | org.hl7.fhir.dstu2016may | Fixed | RHSA-2024:9806 |
| Red Hat build of Apache Camel 4.4.4 for Spring Boot | org.hl7.fhir.dstu3 | Fixed | RHSA-2024:9806 |
| Red Hat build of Apache Camel 4.4.4 for Spring Boot | org.hl7.fhir.r4 | Fixed | RHSA-2024:9806 |
| Red Hat build of Apache Camel 4.4.4 for Spring Boot | org.hl7.fhir.r5 | Fixed | RHSA-2024:9806 |
| Red Hat build of Apache Camel 4.4.4 for Spring Boot | org.hl7.fhir.utilities | Fixed | RHSA-2024:9806 |
| Red Hat Fuse 7 | ca.uhn.hapi.fhir-org.hl7.fhir.core | Fix deferred | n/a |
| Red Hat Fuse 7 | ca.uhn.hapi.fhir/org.hl7.fhir.convertors | Fix deferred | n/a |
| Red Hat Fuse 7 | ca.uhn.hapi.fhir/org.hl7.fhir.validation | Fix deferred | n/a |
| Red Hat Fuse 7 | ca.uhn.hapi.fhir/org.hl7.fhir.validation.cli | Fix deferred | n/a |
| Red Hat Fuse 7 | org.hl7.fhir.dstu2 | Fix deferred | n/a |
| Red Hat Fuse 7 | org.hl7.fhir.dstu2016may | Fix deferred | n/a |
| Red Hat Fuse 7 | org.hl7.fhir.dstu3 | Fix deferred | n/a |
| Red Hat Fuse 7 | org.hl7.fhir.r4 | Fix deferred | n/a |
| Red Hat Fuse 7 | org.hl7.fhir.r5 | Fix deferred | n/a |
| Red Hat Fuse 7 | org.hl7.fhir.utilities | Fix deferred | n/a |
| Red Hat Integration Camel K 1 | org.hl7.fhir.dstu3 | Out of support scope | n/a |
| Red Hat Integration Camel K 1 | org.hl7.fhir.r4 | Out of support scope | n/a |
| Red Hat Integration Camel K 1 | org.hl7.fhir.r5 | Out of support scope | n/a |
| Red Hat Integration Camel K 1 | org.hl7.fhir.utilities | Out of support scope | n/a |
| Red Hat build of Apache Camel for Spring Boot 3 | org.hl7.fhir.dstu2 | Out of support scope | n/a |
| Red Hat build of Apache Camel for Spring Boot 3 | org.hl7.fhir.dstu2016may | Out of support scope | n/a |
| Red Hat build of Apache Camel for Spring Boot 3 | org.hl7.fhir.dstu3 | Out of support scope | n/a |
| Red Hat build of Apache Camel for Spring Boot 3 | org.hl7.fhir.r4 | Out of support scope | n/a |
| Red Hat build of Apache Camel for Spring Boot 3 | org.hl7.fhir.r5 | Out of support scope | n/a |
| Red Hat build of Apache Camel for Spring Boot 3 | org.hl7.fhir.utilities | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Build of Apache Camel K provides support for a select group of extensions for Camel Quarkus. As FHIR is not on this list, it is marked as out of support scope. Consult the external references section for the list of supported Camel Quarkus extension. While Red Hat Fuse 7 includes a vulnerable version of FHIR, the product does not utilize the affected function. This reduces impact of the vulnerability to Low.
Red Hat mitigation
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Nov 6, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (22 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 1.90% (0.01904) | 79.00th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.85% (0.01851) | 76.28th | v5 (v2026.06.15) |
| Mar 27, 2026 | 7.94% (0.07937) | 92.01th | v4 (v2025.03.14) |
| Jan 4, 2026 | 6.00% (0.06005) | 90.39th | v4 (v2025.03.14) |
| Jan 1, 2026 | 4.88% (0.04880) | 89.31th | v4 (v2025.03.14) |
| Dec 14, 2025 | 6.31% (0.06312) | 90.60th | v4 (v2025.03.14) |
| Dec 4, 2025 | 4.23% (0.04226) | 88.33th | v4 (v2025.03.14) |
| Dec 1, 2025 | 2.20% (0.02195) | 83.94th | v4 (v2025.03.14) |
| Nov 28, 2025 | 4.23% (0.04226) | 88.26th | v4 (v2025.03.14) |
| Nov 21, 2025 | 2.20% (0.02195) | 83.87th | v4 (v2025.03.14) |
| Nov 18, 2025 | 12.63% (0.12632) | 93.31th | v4 (v2025.03.14) |
| Aug 22, 2025 | 1.88% (0.01875) | 82.37th | v4 (v2025.03.14) |
| Apr 15, 2025 | 0.78% (0.00777) | 72.28th | v4 (v2025.03.14) |
| Mar 30, 2025 | 4.67% (0.04665) | 88.30th | v4 (v2025.03.14) |
| Mar 29, 2025 | 23.11% (0.23112) | 93.41th | v4 (v2025.03.14) |
| Mar 28, 2025 | 4.67% (0.04665) | 88.32th | v4 (v2025.03.14) |
| Mar 27, 2025 | 39.79% (0.39790) | 96.83th | v4 (v2025.03.14) |
| Mar 23, 2025 | 23.11% (0.23112) | 95.24th | v4 (v2025.03.14) |
| Mar 20, 2025 | 4.67% (0.04665) | 88.40th | v4 (v2025.03.14) |
| Mar 17, 2025 | 23.11% (0.23112) | 95.47th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00043) | 10.81th | v3 (v2023.03.01) |
| Nov 6, 2024 | 0.04% (0.00043) | 10.01th | v3 (v2023.03.01) |
References (9)
- https://access.redhat.com/security/cve/CVE-2024-51132 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2323897 Issue Tracking
- https://docs.redhat.com/en/documentation/red_hat_build_of_apache_camel_k/1.10.8/html/release_notes_for_red_hat_build_of_apache_camel_k/camel-k-relnotes_camelk#supported_camel_quarkus_connector_extensions
- https://github.com/JAckLosingHeart/CVE-2024-51132-POC
- https://github.com/advisories/GHSA-4cf2-cxp3-rjr7 Advisory
- https://github.com/hapifhir/org.hl7.fhir.core
- https://github.com/hapifhir/org.hl7.fhir.core/commit/7ede053a5fca50cc2802884c661a241d51703a67
- https://nvd.nist.gov/vuln/detail/CVE-2024-51132
- https://www.cve.org/CVERecord?id=CVE-2024-51132
Change history (0)
No recorded changes yet.