HealthRecordCommunity
FHIR🌏 InternationalEnriched

CVE-2024-51132: Confidential Information Leakage in HL7 FHIR

CVE-2024-51132: Получение конфиденциальной информации в HL7 FHIR

December 13, 2024

Summary

A critical vulnerability, CVE-2024-51132, has been found in FHIR software (versions 6.0.0–6.3.32). This flaw allows for the leakage of confidential information by exploiting improper restrictions on external entity references within XML.

Details

FHIR-related software versions 6.0.0 through 6.3.32 are affected by a critical vulnerability, CVE-2024-51132. This flaw stems from the incorrect restriction of external references in XML (CWE-611). An attacker can exploit this by sending specially crafted malicious XML code. The severity is rated as CRITICAL (9.1), with a network attack vector, low complexity, and no required privileges. The impact includes high confidentiality and high integrity risks, but no impact on availability. The vulnerability is addressed by an official vendor patch. However, due to the current geopolitical situation and sanctions against the Russian Federation, it is recommended that software updates be installed only after evaluating all associated risks. Exploitation requires sending malicious XML code and does not require user interaction.

📰
Read Original Article
1275.ru

Original content copyright by respective publishers