CVE-2024-51132: Confidential Information Leakage in HL7 FHIR
CVE-2024-51132: Получение конфиденциальной информации в HL7 FHIR
Summary
A critical vulnerability, CVE-2024-51132, has been found in FHIR software (versions 6.0.0–6.3.32). This flaw allows for the leakage of confidential information by exploiting improper restrictions on external entity references within XML.
Details
FHIR-related software versions 6.0.0 through 6.3.32 are affected by a critical vulnerability, CVE-2024-51132. This flaw stems from the incorrect restriction of external references in XML (CWE-611). An attacker can exploit this by sending specially crafted malicious XML code. The severity is rated as CRITICAL (9.1), with a network attack vector, low complexity, and no required privileges. The impact includes high confidentiality and high integrity risks, but no impact on availability. The vulnerability is addressed by an official vendor patch. However, due to the current geopolitical situation and sanctions against the Russian Federation, it is recommended that software updates be installed only after evaluating all associated risks. Exploitation requires sending malicious XML code and does not require user interaction.
Original content copyright by respective publishers