CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-52807: XXE vulnerability in XSLT parsing in `org.hl7.fhir.publisher`

8.6 CVSS

Description

The HL7 FHIR IG publisher is a tool to take a set of inputs and create a standard FHIR IG. Prior to version 1.7.4, XSLT transforms performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag `( ]>` could produce XML containing data from the host system. This impacts use cases where org.hl7.fhir.publisher is being used to within a host where external clients can submit XML. A previous release provided an incomplete solution revealed by new testing. This issue has been patched as of version 1.7.4. No known workarounds are available.

Classification

CVE ID: CVE-2024-52807

CVSS Base Severity: HIGH

CVSS Base Score: 8.6

Affected Products

Vendor: HL7

Product: fhir-ig-publisher

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.72% (scored less or equal to compared to others)

EPSS Date: 2025-02-21 (when was this score calculated)

References

https://github.com/HL7/fhir-ig-publisher/security/advisories/GHSA-8c3x-hq82-gjcm
https://github.com/HL7/fhir-ig-publisher/compare/1.7.3...1.7.4

Timeline