Junglewise Threat Intelligence

CVE-2024-51132: HAPI FHIR XML External Entity (XXE) vulnerability

CVE-2024-51132 · Severity: low · CVSS 3.1 · Published 2024-11-05

Technologies: ca.uhn.hapi.fhir:org.hl7.fhir.utilities (Maven), ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 (Maven), ca.uhn.hapi.fhir:org.hl7.fhir.dstu3 (Maven), ca.uhn.hapi.fhir:org.hl7.fhir.r5 (Maven), ca.uhn.hapi.fhir:org.hl7.fhir.r4 (Maven), ca.uhn.hapi.fhir:org.hl7.fhir.dstu2016may (Maven), ca.uhn.hapi.fhir:org.hl7.fhir.convertors (Maven), ca.uhn.hapi.fhir:org.hl7.fhir.r4b (Maven), ca.uhn.hapi.fhir:org.hl7.fhir.validation (Maven). Vendors: Maven.

Executive brief

HAPI FHIR XML External Entity (XXE) vulnerability

Affected products

  • Maven ca.uhn.hapi.fhir:org.hl7.fhir.utilities
  • Maven ca.uhn.hapi.fhir:org.hl7.fhir.dstu2
  • Maven ca.uhn.hapi.fhir:org.hl7.fhir.dstu3
  • Maven ca.uhn.hapi.fhir:org.hl7.fhir.r5
  • Maven ca.uhn.hapi.fhir:org.hl7.fhir.r4
  • Maven ca.uhn.hapi.fhir:org.hl7.fhir.dstu2016may
  • Maven ca.uhn.hapi.fhir:org.hl7.fhir.convertors
  • Maven ca.uhn.hapi.fhir:org.hl7.fhir.r4b
  • Maven ca.uhn.hapi.fhir:org.hl7.fhir.validation

Related threats