GHSA-gr3c-q7xf-47vh
HIGHCVE-2024-52007XSLT parsing performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag ( <!DOCTYPE foo [<!ENTITY example SYSTEM "/etc/passwd"> ]> could produce XML containing data from the host system. This impacts use cases where org.hl7.fhir.core is being used to within a host where external clients can submit XML.
- Affected
- < 6.4.0
- Fixed in
- 6.4.0
- Published
- 2024-11-08
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereference