FHIR Vulnerabilities: XXE Flaw Found in Ucum-java Library
FHIR 漏洞列表- 1 条CVE - 神龙漏洞库
Summary
A security advisory concerning FHIR has identified an XXE (External Entity) vulnerability within the Ucum-java library, found during XML parsing. This flaw was published on December 13, 2024, with a CVSS score of 8.6 (High).
Details
This page serves as a comprehensive listing of all published CVE security advisories associated with FHIR. The specific vulnerability detailed is an XXE flaw (CWE-611) found in the XML parsing functionality of Ucum-java. For developers utilizing FHIR, which is a critical standard for healthcare data exchange, this advisory is highly relevant. XXE vulnerabilities are serious security flaws that can allow attackers to access sensitive data or execute commands on the server side by exploiting external entities. The report provides clear identification (CVE-2024-55887), an elevated CVSS score of 8.6, and the affected product name. Developers must use this information to verify the versions of their utilized libraries and system components, ensuring prompt patching or implementing alternative mitigation strategies. The platform aims to support rapid vulnerability triage by providing AI-generated analysis in Chinese.
Original content copyright by respective publishers