CVE-2024-52007
- EPSS 0.24%
- Veröffentlicht 08.11.2024 23:15:04
- Zuletzt bearbeitet 12.11.2024 13:56:54
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. XSLT parsing performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag ( <!...
CVE-2023-28465
- EPSS 0.55%
- Veröffentlicht 12.12.2023 17:15:07
- Zuletzt bearbeitet 27.05.2025 15:15:29
The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to certain directories via directory traversal, if an allowed directory name is a substring of the directory name ch...
CVE-2023-24057
- EPSS 0.93%
- Veröffentlicht 26.01.2023 21:18:15
- Zuletzt bearbeitet 01.04.2025 20:15:16
HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via directory traversal from a crafted ZIP or TGZ archive (for a prepackaged terminology cache, NPM package, or comparison archive).