CVE-2024-51132
CRITICALCa.uhn.hapi.fhir Org.hl7.fhir.convertors < 6.4.0 - XXE
Title source: ruleDescription
An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.
Exploits (1)
nomisec
WORKING POC
1 stars
by JAckLosingHeart · poc
https://github.com/JAckLosingHeart/CVE-2024-51132-POC
Scores
CVSS v3
9.8
EPSS
0.0794
EPSS Percentile
92.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-611
Status
published
Products (9)
ca.uhn.hapi.fhir/org.hl7.fhir.convertors
0 - 6.4.0Maven
ca.uhn.hapi.fhir/org.hl7.fhir.dstu2
0 - 6.4.0Maven
ca.uhn.hapi.fhir/org.hl7.fhir.dstu2016may
0 - 6.4.0Maven
ca.uhn.hapi.fhir/org.hl7.fhir.dstu3
0 - 6.4.0Maven
ca.uhn.hapi.fhir/org.hl7.fhir.r4
0 - 6.4.0Maven
ca.uhn.hapi.fhir/org.hl7.fhir.r4b
0 - 6.4.0Maven
ca.uhn.hapi.fhir/org.hl7.fhir.r5
0 - 6.4.0Maven
ca.uhn.hapi.fhir/org.hl7.fhir.utilities
0 - 6.4.0Maven
ca.uhn.hapi.fhir/org.hl7.fhir.validation
0 - 6.4.0Maven
Published
Nov 05, 2024
Tracked Since
Feb 18, 2026