CVE-2024-51132

CRITICAL

Ca.uhn.hapi.fhir Org.hl7.fhir.convertors < 6.4.0 - XXE

Title source: rule

Description

An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.

Exploits (1)

nomisec WORKING POC 1 stars
by JAckLosingHeart · poc
https://github.com/JAckLosingHeart/CVE-2024-51132-POC

Scores

CVSS v3 9.8
EPSS 0.0794
EPSS Percentile 92.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-611
Status published
Products (9)
ca.uhn.hapi.fhir/org.hl7.fhir.convertors 0 - 6.4.0Maven
ca.uhn.hapi.fhir/org.hl7.fhir.dstu2 0 - 6.4.0Maven
ca.uhn.hapi.fhir/org.hl7.fhir.dstu2016may 0 - 6.4.0Maven
ca.uhn.hapi.fhir/org.hl7.fhir.dstu3 0 - 6.4.0Maven
ca.uhn.hapi.fhir/org.hl7.fhir.r4 0 - 6.4.0Maven
ca.uhn.hapi.fhir/org.hl7.fhir.r4b 0 - 6.4.0Maven
ca.uhn.hapi.fhir/org.hl7.fhir.r5 0 - 6.4.0Maven
ca.uhn.hapi.fhir/org.hl7.fhir.utilities 0 - 6.4.0Maven
ca.uhn.hapi.fhir/org.hl7.fhir.validation 0 - 6.4.0Maven
Published Nov 05, 2024
Tracked Since Feb 18, 2026