hapifhir kayıtları
hapifhir üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %88,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-1333 Inefficient Regular Expression Complexity1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-918 Server-Side Request Forgery (SSRF)1
- CWE-552 Files or Directories Accessible to External Parties1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
37İzleyin | CVE-2026-34361İstismar yok | HAPI FHIR: Unauthenticated SSRF via /loadIG Chains with startsWith() Credential Leak for Authentication Token Thefthapifhir · hl7 fhir core · CWE-552 | Kritik9,3 | — | %0,4 | 31 Mar 2026 |
36İzleyin | CVE-2026-34359İstismar yok | HAPI FHIR: Authentication Credential Leakage via Improper URL Prefix Matching on HTTP Redirect in HAPI FHIR Corehapifhir · hl7 fhir core · CWE-346 | Kritik9,1 | — | %0,2 | 31 Mar 2026 |
34İzleyin | CVE-2024-52007İstismar yok | XXE vulnerability in XSLT parsing in `org.hl7.fhir.core`hapifhir · org.hl7.fhir.core · CWE-611 | Yüksek8,6 | — | %0,9 | 8 Kas 2024 |
34İzleyin | CVE-2026-55471İstismar yok | HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactoryhapifhir · hl7 fhir core · CWE-611 | Yüksek8,7 | — | %0,6 | 8 Tem 2026 |
32İzleyin | CVE-2023-24057İstismar yok | HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via directory traversal fhl7 · fhir ig publisher · CWE-22 | Yüksek8,1 | — | %1,2 | 26 Oca 2023 |
30İzleyin | CVE-2023-28465Kavram kanıtı | The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to cerhapifhir · hl7 fhir core · CWE-22 | Yüksek7,5 | — | %1,3 | 12 Ara 2023 |
30İzleyin | CVE-2026-55470İstismar yok | HAPI FHIR: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoShapifhir · hl7 fhir core · CWE-1333 | Yüksek7,5 | — | %0,7 | 8 Tem 2026 |
24İzleyin | CVE-2020-24301İstismar yok | Users of the HAPI FHIR Testpage Overlay 5.0.0 and below can use a specially crafted URL to exploit an XSS vulnerability in this module, allohapifhir · testpage overlay · CWE-79 | Orta6,1 | — | %0,9 | 8 Eki 2020 |
23İzleyin | CVE-2026-34360İstismar yok | HAPI FHIR: Unauthenticated Blind SSRF via /loadIG Endpoint Enables Internal Network Probinghapifhir · hl7 fhir core · CWE-918 | Orta5,8 | — | %0,3 | 31 Mar 2026 |
- CVE-2026-3436137İzleyin
HAPI FHIR: Unauthenticated SSRF via /loadIG Chains with startsWith() Credential Leak for Authentication Token Theft
KritikCVSS 9,3İstismar yokEPSS %0hapifhir · hl7 fhir core31 Mar 2026
- CVE-2026-3435936İzleyin
HAPI FHIR: Authentication Credential Leakage via Improper URL Prefix Matching on HTTP Redirect in HAPI FHIR Core
KritikCVSS 9,1İstismar yokEPSS %0hapifhir · hl7 fhir core31 Mar 2026
- CVE-2024-5200734İzleyin
XXE vulnerability in XSLT parsing in `org.hl7.fhir.core`
YüksekCVSS 8,6İstismar yokEPSS %1hapifhir · org.hl7.fhir.core8 Kas 2024
- CVE-2026-5547134İzleyin
HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory
YüksekCVSS 8,7İstismar yokEPSS %1hapifhir · hl7 fhir core8 Tem 2026
- CVE-2023-2405732İzleyin
HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via directory traversal f
YüksekCVSS 8,1İstismar yokEPSS %1hl7 · fhir ig publisher26 Oca 2023
- CVE-2023-2846530İzleyin
The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to cer
YüksekCVSS 7,5Kavram kanıtıEPSS %1hapifhir · hl7 fhir core12 Ara 2023
- CVE-2026-5547030İzleyin
HAPI FHIR: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS
YüksekCVSS 7,5İstismar yokEPSS %1hapifhir · hl7 fhir core8 Tem 2026
- CVE-2020-2430124İzleyin
Users of the HAPI FHIR Testpage Overlay 5.0.0 and below can use a specially crafted URL to exploit an XSS vulnerability in this module, allo
OrtaCVSS 6,1İstismar yokEPSS %1hapifhir · testpage overlay8 Eki 2020
- CVE-2026-3436023İzleyin
HAPI FHIR: Unauthenticated Blind SSRF via /loadIG Endpoint Enables Internal Network Probing
OrtaCVSS 5,8İstismar yokEPSS %0hapifhir · hl7 fhir core31 Mar 2026