Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
  Github GHSA | 
                GHSA-4cf2-cxp3-rjr7 | HAPI FHIR XML External Entity (XXE) vulnerability | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        epss
         
  | 
    
        
        
        epss
         
  | 
Sat, 07 Dec 2024 02:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Redhat camel Quarkus
         | 
|
| CPEs | cpe:/a:redhat:camel_quarkus:3.8 | |
| Vendors & Products | 
        
        Redhat camel Quarkus
         | 
Sat, 16 Nov 2024 02:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Redhat
         Redhat apache Camel Spring Boot  | 
|
| CPEs | cpe:/a:redhat:apache_camel_spring_boot:4.4.4 | |
| Vendors & Products | 
        
        Redhat
         Redhat apache Camel Spring Boot  | 
Wed, 13 Nov 2024 02:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | 
Sat, 09 Nov 2024 02:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Title | org.hl7.fhir.convertors: org.hl7.fhir.dstu2: org.hl7.fhir.dstu2016may: org.hl7.fhir.dstu3: org.hl7.fhir.r4: org.hl7.fhir.r5: org.hl7.fhir.utilities: org.hl7.fhir.validation: org.hl7.fhir.core: arbitrary code execution via specially-crafted request | org.hl7.fhir.convertors: org.hl7.fhir.dstu2: org.hl7.fhir.dstu2016may: org.hl7.fhir.dstu3: org.hl7.fhir.r4: org.hl7.fhir.r5: org.hl7.fhir.utilities: org.hl7.fhir.validation: org.hl7.fhir.core: FHIR arbitrary code execution via specially-crafted request | 
Thu, 07 Nov 2024 02:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Title | org.hl7.fhir.convertors: org.hl7.fhir.dstu2: org.hl7.fhir.dstu2016may: org.hl7.fhir.dstu3: org.hl7.fhir.r4: org.hl7.fhir.r5: org.hl7.fhir.utilities: org.hl7.fhir.validation: org.hl7.fhir.core: arbitrary code execution via specially-crafted request | |
| Weaknesses | CWE-601 | |
| References | 
         | |
| Metrics | 
        
        
        threat_severity
         
  | 
    
        
        cvssV3_0
         
 
  | 
Wed, 06 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Fhir
         Fhir hapi Fhir  | 
|
| Weaknesses | CWE-611 | |
| CPEs | cpe:2.3:a:fhir:hapi_fhir:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Fhir
         Fhir hapi Fhir  | 
|
| Metrics | 
        
        cvssV3_1
         
 
  | 
Tue, 05 Nov 2024 17:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities. | |
| References | 
         | 
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-06T19:23:22.420Z
Reserved: 2024-10-28T00:00:00
Link: CVE-2024-51132
Updated: 2024-11-06T19:23:15.126Z
Status : Awaiting Analysis
Published: 2024-11-05T17:15:07.310
Modified: 2024-11-06T20:35:34.173
Link: CVE-2024-51132
                        OpenCVE Enrichment
                    No data.
 Github GHSA