CVE-2021-32053
Summary
| CVE | CVE-2021-32053 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-10 21:15:00 UTC |
| Updated | 2021-05-19 17:11:00 UTC |
| Description | JPA Server in HAPI FHIR before 5.4.0 allows a user to deny service (e.g., disable access to the database after the attack stops) via history requests. This occurs because of a SELECT COUNT statement that requires a full index scan, with an accompanying large amount of server resources if there are many simultaneous history requests. |
Risk And Classification
Problem Types: CWE-400
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| HAPI FHIR - The Open Source FHIR API for Java | MISC | hapifhir.io | |
| Resolve weakness in history operation by jamesagnew · Pull Request #2642 · hapifhir/hapi-fhir · GitHub | MISC | github.com | |
| Potential Denial of Service in JPA Server via history operation · Issue #2641 · hapifhir/hapi-fhir · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982239 Java (maven) Security Update for ca.uhn.hapi.fhir:hapi-fhir-jpaserver-base (GHSA-67f6-c8mx-4q2m)