Vulnerability (CVE-2024-52807) Found in HL7 FHIR Leading to Data Leakage
HL7 FHIR - CVE-2024-52807 | Portail du CERT SantΓ©
Summary
A vulnerability was reported in the Health Level 7 (HL7) FHIR standard, allowing data confidentiality breaches. An attacker can steal data by sending a specially crafted XML file.
Details
Fast Healthcare Interoperability Resources (FHIR) is a standard created by Health Level 7 (HL7) for exchanging health data. A flaw in the data control within HL7 FHIR was discovered. Specifically, vulnerability CVE-2024-52807 points to 'CWE-611: Improper Restriction of XML External Entity Reference.' An attacker can compromise the confidentiality of data by sending a specially crafted XML file. This vulnerability is exploitable over the network, requires low complexity for attack, and no special privileges are needed. Affected components include versions prior to 1.7.4 of `org.hl7.fhir.publisher.cli` and `org.hl7.fhir.publisher.core`. To mitigate this risk, it is recommended that FHIR-related components be updated immediately to version 1.7.4 or later. HL7 provides further details.
Original content copyright by respective publishers