Lucene search

K
cveMitreCVE-2023-24057
HistoryJan 26, 2023 - 9:18 p.m.

CVE-2023-24057

2023-01-2621:18:15
CWE-22
mitre
web.nvd.nist.gov
80
hl7
fhir
core libraries
security vulnerability
cve-2023-24057
nvd

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0.002

Percentile

61.6%

HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via directory traversal from a crafted ZIP or TGZ archive (for a prepackaged terminology cache, NPM package, or comparison archive).

Affected configurations

Nvd
Node
hapifhirhl7_fhir_coreRange<5.6.92
OR
hl7fhir_ig_publisherRange<1.2.30
VendorProductVersionCPE
hapifhirhl7_fhir_core*cpe:2.3:a:hapifhir:hl7_fhir_core:*:*:*:*:*:*:*:*
hl7fhir_ig_publisher*cpe:2.3:a:hl7:fhir_ig_publisher:*:*:*:*:*:*:*:*

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0.002

Percentile

61.6%