CVE-2024-52807

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Jan 24, 2025
CWE ID 611

Summary

CVE-2024-52807 is a vulnerability affecting the HL7 FHIR IG publisher before version 1.7.4. This tool creates FHIR Implementation Guides from inputs. The vulnerability lies in the XSLT transforms used by various components, which can be exploited through XML external entity injections. A malicious XML file incorporating a malicious DTD tag `[ ]>` could result in the processing of data from the host system. This issue is significant as it impacts hosts where org.hl7.fhir.publisher is utilized and external clients can submit XML. A previous patch attempt in a previous release was found to be incomplete, but version 1.7.4 has successfully addressed this vulnerability. Currently, no workarounds are available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share