{"id":"CVE-2024-52007","aliases":["GHSA-gr3c-q7xf-47vh"],"url":"https://o3.security/vulnerability/CVE-2024-52007","summary":"XXE vulnerability in XSLT parsing in `org.hl7.fhir.core`","details":"HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. XSLT parsing performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag ( <!DOCTYPE foo [<!ENTITY example SYSTEM \"/etc/passwd\"> ]> could produce XML containing data from the host system. This impacts use cases where org.hl7.fhir.core is being used to within a host where external clients can submit XML. This is related to GHSA-6cr6-ph3p-f5rf, in which its fix (#1571 & #1717) was incomplete. This issue has been addressed in release version 6.4.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.","published":"2024-11-08T22:28:20.169Z","modified":"2026-08-12T03:51:22.077492249Z","cvss":{"score":8.6,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"},"epss":{"score":0.00899,"percentile":0.57935,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"ca.uhn.hapi.fhir:org.hl7.fhir.dstu3","fixedVersion":"6.4.0"},{"ecosystem":"Maven","name":"ca.uhn.hapi.fhir:org.hl7.fhir.r4","fixedVersion":"6.4.0"},{"ecosystem":"Maven","name":"ca.uhn.hapi.fhir:org.hl7.fhir.r4b","fixedVersion":"6.4.0"},{"ecosystem":"Maven","name":"ca.uhn.hapi.fhir:org.hl7.fhir.r5","fixedVersion":"6.4.0"},{"ecosystem":"Maven","name":"ca.uhn.hapi.fhir:org.hl7.fhir.utilities","fixedVersion":"6.4.0"},{"ecosystem":"Maven","name":"ca.uhn.hapi.fhir:org.hl7.fhir.dstu2016may","fixedVersion":"6.4.0"}],"fix":{"url":"https://github.com/hapifhir/org.hl7.fhir.core/pull/1717","label":"hapifhir/org.hl7.fhir.core#1717"},"references":[{"type":"WEB","url":"https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html#jaxp-documentbuilderfactory-saxparserfactory-and-dom4j"},{"type":"WEB","url":"https://cwe.mitre.org/data/definitions/611.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/52xxx/CVE-2024-52007.json"},{"type":"ADVISORY","url":"https://github.com/hapifhir/org.hl7.fhir.core/security/advisories/GHSA-6cr6-ph3p-f5rf"},{"type":"ADVISORY","url":"https://github.com/hapifhir/org.hl7.fhir.core/security/advisories/GHSA-gr3c-q7xf-47vh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-52007"},{"type":"REPORT","url":"https://github.com/hapifhir/org.hl7.fhir.core/issues/1571"},{"type":"FIX","url":"https://github.com/hapifhir/org.hl7.fhir.core/pull/1717"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:22.077492249Z"}}