ca.uhn.hapi.fhir:org.hl7.fhir.r5@5.6.101 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the ca.uhn.hapi.fhir:org.hl7.fhir.r5 package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Arbitrary File Write via Archive Extraction (Zip Slip)

Affected versions of this package are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) this is due to a bypass of CVE-2023-24057. This issue allows a malicious actor to potentially break out of the TerminologyCacheManager cache directory. The impact is limited to sibling directories.

For example, consider "/usr/outnot".startsWith("/usr/out"). The check is bypassed although /outnot is not under the /out directory.

How to fix Arbitrary File Write via Archive Extraction (Zip Slip)?

Upgrade ca.uhn.hapi.fhir:org.hl7.fhir.r5 to version 5.6.106 or higher.

[,5.6.106)