CVE-2019-12741

Name
CVE-2019-12741
Description
XSS exists in the HAPI FHIR testpage overlay module of the HAPI FHIR library before 3.8.0. The attack involves unsanitized HTTP parameters being output in a form page, allowing attackers to leak cookies and other sensitive information from ca/uhn/fhir/to/BaseController.java via a specially crafted URL. (This module is not generally used in production systems so the attack surface is expected to be low, but affected systems are recommended to upgrade immediately.)
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Third Party Advisory https://github.com/jamesagnew/hapi-fhir/releases/tag/v3.8.0
Patch https://github.com/jamesagnew/hapi-fhir/issues/1335
Patch https://github.com/jamesagnew/hapi-fhir/commit/8f41159eb147eeb964cad68b28eff97acac6ea9a

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:fhir:hapi_fhir:*:*:*:*:*:*:*:* hapi_fhir >= None < 3.8.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
nomad edge-community 0.9.6-r0 None fixed
nomad 3.18-community 0.9.6-r0 None fixed
nomad 3.17-community 0.9.6-r0 None fixed