ca.uhn.hapi.fhir:org.hl7.fhir.r4b@5.6.103 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the ca.uhn.hapi.fhir:org.hl7.fhir.r4b package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Arbitrary File Write via Archive Extraction (Zip Slip)

Affected versions of this package are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) this is due to a bypass of CVE-2023-24057. This issue allows a malicious actor to potentially break out of the TerminologyCacheManager cache directory. The impact is limited to sibling directories.

For example, consider "/usr/outnot".startsWith("/usr/out"). The check is bypassed although /outnot is not under the /out directory.

How to fix Arbitrary File Write via Archive Extraction (Zip Slip)?

Upgrade ca.uhn.hapi.fhir:org.hl7.fhir.r4b to version 5.6.106 or higher.

[,5.6.106)