XXE vulnerability in XSLT parsing in `org.hl7.fhir.core`
Published Nov 8, 2024
7.7
HIGHCVSS 4.0
EPSS 0.90%
Description
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. XSLT parsing performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag ( <!DOCTYPE foo [<!ENTITY example SYSTEM "/etc/passwd"> ]> could produce XML containing data from the host system. This impacts use cases where org.hl7.fhir.core is being used to within a host where external clients can submit XML. This is related to GHSA-6cr6-ph3p-f5rf, in which its fix (#1571 & #1717) was incomplete. This issue has been addressed in release version 6.4.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected products
-
- Version < 6.4.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Hapifhir | Org.hl7.fhir.core | n/a |
|
No data.
-
- Version 0StatusaffectedConstraints<6.4.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Hapifhir | Hl7 Fhir Core | n/a |
|
Red Hat build of Apache Camel 4.4.4 for Spring Boot
org.hl7.fhir.dstu2016may
Fixed · RHSA-2024:9806
Red Hat build of Apache Camel 4.4.4 for Spring Boot
org.hl7.fhir.dstu3
Fixed · RHSA-2024:9806
Red Hat build of Apache Camel 4.4.4 for Spring Boot
org.hl7.fhir.r4
Fixed · RHSA-2024:9806
Red Hat build of Apache Camel 4.4.4 for Spring Boot
org.hl7.fhir.r5
Fixed · RHSA-2024:9806
Red Hat build of Apache Camel 4.4.4 for Spring Boot
org.hl7.fhir.utilities
Fixed · RHSA-2024:9806
Red Hat Fuse 7
ca.uhn.hapi.fhir-org.hl7.fhir.core
Will not fix
Red Hat Fuse 7
org.hl7.fhir.dstu2016may
Will not fix
Red Hat Fuse 7
org.hl7.fhir.dstu3
Will not fix
Red Hat Fuse 7
org.hl7.fhir.r4
Will not fix
Red Hat Fuse 7
org.hl7.fhir.r5
Will not fix
Red Hat Fuse 7
org.hl7.fhir.utilities
Will not fix
Red Hat Integration Camel K 1
org.hl7.fhir.dstu3
Will not fix
Red Hat Integration Camel K 1
org.hl7.fhir.r4
Will not fix
Red Hat Integration Camel K 1
org.hl7.fhir.r5
Will not fix
Red Hat Integration Camel K 1
org.hl7.fhir.utilities
Will not fix
Red Hat build of Apache Camel for Spring Boot 3
org.hl7.fhir.dstu2016may
Out of support scope
Red Hat build of Apache Camel for Spring Boot 3
org.hl7.fhir.dstu3
Out of support scope
Red Hat build of Apache Camel for Spring Boot 3
org.hl7.fhir.r4
Out of support scope
Red Hat build of Apache Camel for Spring Boot 3
org.hl7.fhir.r5
Out of support scope
Red Hat build of Apache Camel for Spring Boot 3
org.hl7.fhir.utilities
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat build of Apache Camel 4.4.4 for Spring Boot | org.hl7.fhir.dstu2016may | Fixed | RHSA-2024:9806 |
| Red Hat build of Apache Camel 4.4.4 for Spring Boot | org.hl7.fhir.dstu3 | Fixed | RHSA-2024:9806 |
| Red Hat build of Apache Camel 4.4.4 for Spring Boot | org.hl7.fhir.r4 | Fixed | RHSA-2024:9806 |
| Red Hat build of Apache Camel 4.4.4 for Spring Boot | org.hl7.fhir.r5 | Fixed | RHSA-2024:9806 |
| Red Hat build of Apache Camel 4.4.4 for Spring Boot | org.hl7.fhir.utilities | Fixed | RHSA-2024:9806 |
| Red Hat Fuse 7 | ca.uhn.hapi.fhir-org.hl7.fhir.core | Will not fix | n/a |
| Red Hat Fuse 7 | org.hl7.fhir.dstu2016may | Will not fix | n/a |
| Red Hat Fuse 7 | org.hl7.fhir.dstu3 | Will not fix | n/a |
| Red Hat Fuse 7 | org.hl7.fhir.r4 | Will not fix | n/a |
| Red Hat Fuse 7 | org.hl7.fhir.r5 | Will not fix | n/a |
| Red Hat Fuse 7 | org.hl7.fhir.utilities | Will not fix | n/a |
| Red Hat Integration Camel K 1 | org.hl7.fhir.dstu3 | Will not fix | n/a |
| Red Hat Integration Camel K 1 | org.hl7.fhir.r4 | Will not fix | n/a |
| Red Hat Integration Camel K 1 | org.hl7.fhir.r5 | Will not fix | n/a |
| Red Hat Integration Camel K 1 | org.hl7.fhir.utilities | Will not fix | n/a |
| Red Hat build of Apache Camel for Spring Boot 3 | org.hl7.fhir.dstu2016may | Out of support scope | n/a |
| Red Hat build of Apache Camel for Spring Boot 3 | org.hl7.fhir.dstu3 | Out of support scope | n/a |
| Red Hat build of Apache Camel for Spring Boot 3 | org.hl7.fhir.r4 | Out of support scope | n/a |
| Red Hat build of Apache Camel for Spring Boot 3 | org.hl7.fhir.r5 | Out of support scope | n/a |
| Red Hat build of Apache Camel for Spring Boot 3 | org.hl7.fhir.utilities | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability is of important severity rather than moderate due to its potential to expose sensitive host data and compromise system integrity. By exploiting the XXE vulnerability, an attacker can read arbitrary files (e.g., `/etc/passwd`), perform Denial of Service (DoS) through resource exhaustion, or even execute further attacks by leveraging accessible information.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Nov 12, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (5 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.90% (0.00899) | 58.24th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.92% (0.00918) | 55.39th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.19% (0.00192) | 38.98th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.05% (0.00047) | 19.53th | v3 (v2023.03.01) |
| Nov 9, 2024 | 0.05% (0.00047) | 18.73th | v3 (v2023.03.01) |
References (11)
- https://access.redhat.com/security/cve/CVE-2024-52007 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2324794 Issue Tracking
- https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html#jaxp-documentbuilderfactory-saxparserfactory-and-dom4j x_refsource_MISC
- https://cwe.mitre.org/data/definitions/611.html x_refsource_MISC
- https://github.com/advisories/GHSA-gr3c-q7xf-47vh Advisory
- https://github.com/hapifhir/org.hl7.fhir.core/issues/1571 x_refsource_MISC
- https://github.com/hapifhir/org.hl7.fhir.core/pull/1717 x_refsource_MISC
- https://github.com/hapifhir/org.hl7.fhir.core/security/advisories/GHSA-6cr6-ph3p-f5rf x_refsource_MISC
- https://github.com/hapifhir/org.hl7.fhir.core/security/advisories/GHSA-gr3c-q7xf-47vh x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2024-52007
- https://www.cve.org/CVERecord?id=CVE-2024-52007
Change history (0)
No recorded changes yet.