An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| ca.uhn.hapi.fhir:org.hl7.fhir.convertors(Maven) | 0 | 6.4.0 | N/A |
| ca.uhn.hapi.fhir:org.hl7.fhir.dstu2(Maven) | 0 | 6.4.0 | N/A |
| ca.uhn.hapi.fhir:org.hl7.fhir.dstu2016may(Maven) | 0 | 6.4.0 | N/A |
| ca.uhn.hapi.fhir:org.hl7.fhir.dstu3(Maven) | 0 | 6.4.0 | N/A |
| ca.uhn.hapi.fhir:org.hl7.fhir.r4(Maven) | 0 | 6.4.0 | N/A |
| ca.uhn.hapi.fhir:org.hl7.fhir.r4b(Maven) | 0 | 6.4.0 | N/A |
| ca.uhn.hapi.fhir:org.hl7.fhir.r5(Maven) | 0 | 6.4.0 | N/A |
| ca.uhn.hapi.fhir:org.hl7.fhir.utilities(Maven) | 0 | 6.4.0 | N/A |
| ca.uhn.hapi.fhir:org.hl7.fhir.validation(Maven) | 0 | 6.4.0 | N/A |
CVSS Metrics