CVE-2024-52807: XXE vulnerability in XSLT parsing in `org.hl7.fhir.publisher`
(updated )
XSLT transforms performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag ( ]> could produce XML containing data from the host system. This impacts use cases where org.hl7.fhir.publisher is being used to within a host where external clients can submit XML.
A previous release provided an incomplete solution revealed by new testing.
References
- github.com/HL7/fhir-ig-publisher
- github.com/HL7/fhir-ig-publisher/commit/3560de2f486d688a3ddcf4aa54d8bdacea380c3d
- github.com/HL7/fhir-ig-publisher/compare/1.7.3...1.7.4
- github.com/HL7/fhir-ig-publisher/security/advisories/GHSA-59rq-22fm-x8q5
- github.com/HL7/fhir-ig-publisher/security/advisories/GHSA-8c3x-hq82-gjcm
- github.com/advisories/GHSA-8c3x-hq82-gjcm
- nvd.nist.gov/vuln/detail/CVE-2024-52807
Code Behaviors & Features
Detect and mitigate CVE-2024-52807 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →