CVE-2024-52007
Last modified
CVE-2024-52007 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. XSLT parsing performed by various components are vulnerable to XML external entity injections. EPSS estimates a 0.92% chance of exploitation in the next 30 days.
Description
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. XSLT parsing performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag ( <!DOCTYPE foo [<!ENTITY example SYSTEM "/etc/passwd"> ]> could produce XML containing data from the host system. This impacts use cases where org.hl7.fhir.core is being used to within a host where external clients can submit XML. This is related to GHSA-6cr6-ph3p-f5rf, in which its fix (#1571 & #1717) was incomplete. This issue has been addressed in release version 6.4.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-52007?
How severe is CVE-2024-52007?
How do I fix CVE-2024-52007?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-52001Combodo iTop is a simple, web based IT Service Management to…4.3
- CVE-2024-52002Combodo iTop is a simple, web based IT Service Management to…8.8
- CVE-2024-52003Traefik (pronounced traffic) is an HTTP reverse proxy and lo…6.1
- CVE-2024-52004MediaCMS is an open source video and media CMS, written in P…8.7
- CVE-2024-52005Git is a source code management tool. When cloning from a se…8.8
- CVE-2024-52006Git is a fast, scalable, distributed revision control system…7.5
- CVE-2024-52008Fides is an open-source privacy engineering platform. The us…8.8
- CVE-2024-52009Atlantis is a self-hosted golang application that listens fo…9.8
- CVE-2024-5201Privilege Escalation in OpenText Dimensions RM allows an aut…8.8
- CVE-2024-52010Zoraxy is a general purpose HTTP reverse proxy and forwardin…8.6
- CVE-2024-52011launch-editor allows users to open files with line numbers i…8.3
- CVE-2024-52012Relative Path Traversal vulnerability in Apache Solr. Solr …5.4
Are you affected by CVE-2024-52007?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
