Multiple Security Vulnerabilities Reported in HAPI FHIR Library
ca.uhn.hapi.fhir:org.hl7.fhir.dstu3 Security Advisories - Maven | Ecosyste.ms Ecosyste.ms Security advisories
ca.uhn.hapi.fhir published security advisories related to the FHIR DSTU3 implementation.
Summary
Several critical security vulnerabilities, including ReDoS, authentication leaks, and XXE, have been discovered in HAPI FHIR, an open-source implementation of FHIR. These issues stem from the use of FHIRPath and processing within HTTP endpoints, affecting a wide range of versions.
Key Players
Details
This information is derived from a security advisory aggregation page for HAPI FHIR (ca.uhn.hapi.fhir:org.hl7.fhir.dstu3), an open-source Java implementation library based on the FHIR specification. Multiple severe vulnerabilities have been reported, including ReDoS (Regular Expression Denial of Service) in `matches()` and `replaceMatches()` using FHIRPath, which affects numerous versions. Additionally, classic vulnerabilities such as HTTP authentication leaks and XML External Entity (XXE) are confirmed. Since these flaws originate from core functions related to data processing and communication protocols, they pose a threat to overall system reliability. In the Japanese healthcare IT environment, where FHIR adoption is advancing, security measures at the library level are critically important. Users must check all potentially affected versions and apply the latest patches or implement proper input validation. The reported vulnerabilities include ReDoS (High/Critical), authentication leaks (Critical), and XXE (High), each having different technical origins, necessitating a comprehensive security review. This information is intended for developers as a reference; users must follow official patching procedures.
Technology Note
FHIR(Fast Healthcare Interoperability Resources)は医療データ交換の国際標準。このエントリの関連技術: HL7
Original content copyright by respective publishers