Back

HIGH

XXE vulnerability in XSLT parsing in `org.hl7.fhir.core`

Published Nov 8, 2024

Description

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. XSLT parsing performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag ( <!DOCTYPE foo [<!ENTITY example SYSTEM "/etc/passwd"> ]> could produce XML containing data from the host system. This impacts use cases where org.hl7.fhir.core is being used to within a host where external clients can submit XML. This is related to GHSA-6cr6-ph3p-f5rf, in which its fix (#1571 & #1717) was incomplete. This issue has been addressed in release version 6.4.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

Affected products

Remediation

Red Hat statement

This vulnerability is of important severity rather than moderate due to its potential to expose sensitive host data and compromise system integrity. By exploiting the XXE vulnerability, an attacker can read arbitrary files (e.g., `/etc/passwd`), perform Denial of Service (DoS) through resource exhaustion, or even execute further attacks by leveraging accessible information.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Nov 8, 2024
Updated Nov 12, 2024
Reserved Nov 4, 2024
CISA Vulnrichment
Updated Nov 12, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Nov 8, 2024
GHSA-GR3C-Q7XF-47VH