GHSA-8c3x-hq82-gjcm
HIGHCVE-2024-52807XSLT transforms performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag ( ]> could produce XML containing data from the host system. This impacts use cases where org.hl7.fhir.publisher is being used to within a host where external clients can submit XML.
- Affected
- < 1.7.4
- Fixed in
- 1.7.4
- Weakness
- CWE-611
- Published
- 2025-01-24
- Source
- github