CVE-2019-12741
Last modified
CVE-2019-12741 is a vulnerability of currently unknown severity. XSS exists in the HAPI FHIR testpage overlay module of the HAPI FHIR library before 3.8.0. The attack involves unsanitized HTTP parameters being output in a form page, allowing attackers to leak cookies and other sensitive information from ca/uhn/fhir/to/BaseController.java via a specially crafted URL. EPSS estimates a 1.27% chance of exploitation in the next 30 days.
Description
XSS exists in the HAPI FHIR testpage overlay module of the HAPI FHIR library before 3.8.0. The attack involves unsanitized HTTP parameters being output in a form page, allowing attackers to leak cookies and other sensitive information from ca/uhn/fhir/to/BaseController.java via a specially crafted URL. (This module is not generally used in production systems so the attack surface is expected to be low, but affected systems are recommended to upgrade immediately.)
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fhir | Hapi Fhir | < 3.8.0 |
References
- https://github.com/jamesagnew/hapi-fhir/commit/8f41159eb147eeb964cad68b28eff97acac6ea9aPatch, Third Party Advisory
- https://github.com/jamesagnew/hapi-fhir/issues/1335Patch, Third Party Advisory
- https://github.com/jamesagnew/hapi-fhir/releases/tag/v3.8.0Third Party Advisory
- https://github.com/jamesagnew/hapi-fhir/commit/8f41159eb147eeb964cad68b28eff97acac6ea9aPatch, Third Party Advisory
- https://github.com/jamesagnew/hapi-fhir/issues/1335Patch, Third Party Advisory
- https://github.com/jamesagnew/hapi-fhir/releases/tag/v3.8.0Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-12741?
How severe is CVE-2019-12741?
How do I fix CVE-2019-12741?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-12734SiteVision 4 has Incorrect Access Control.8.8
- CVE-2019-12735getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 all…
- CVE-2019-12736JetBrains Ktor framework before 1.2.0-rc does not sanitize t…9.8
- CVE-2019-12737UserHashedTableAuth in JetBrains Ktor framework before 1.2.0…5.3
- CVE-2019-12739lib/Controller/ExtractionController.php in the Extract add-o…9
- CVE-2019-1274An information disclosure vulnerability exists when the Wind…5.5
- CVE-2019-12742Bludit prior to 3.9.1 allows a non-privileged user to change…
- CVE-2019-12743HumHub Social Network Kit Enterprise v1.3.13 allows remote a…
- CVE-2019-12744SeedDMS before 5.1.11 allows Remote Command Execution (RCE) …
- CVE-2019-12745out/out.UsrMgr.php in SeedDMS before 5.1.11 allows Stored Cr…
- CVE-2019-12746An issue was discovered in Open Ticket Request System (OTRS)…6.5
- CVE-2019-12747TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deseri…8.8
Are you affected by CVE-2019-12741?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
