QID 981747
QID 981747: Java (maven) Security Update for ca.uhn.hapi.fhir:hapi-fhir-base (GHSA-52mh-p2m2-w625)
XSS exists in the HAPI FHIR testpage overlay module of the HAPI FHIR library before 3.8.0. The attack involves unsanitized HTTP parameters being output in a form page, allowing attackers to leak cookies and other sensitive information from ca/uhn/fhir/to/BaseController.java via a specially crafted URL. (This module is not generally used in production systems so the attack surface is expected to be low, but affected systems are recommended to upgrade immediately.)
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-52mh-p2m2-w625 for updates pertaining to this vulnerability.
Vendor References
- GHSA-52mh-p2m2-w625 -
github.com/advisories/GHSA-52mh-p2m2-w625
CVEs related to QID 981747
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-52mh-p2m2-w625 | ca.uhn.hapi.fhir:hapi-fhir-base |
|