Critical severityNVD Advisory· Published Jan 24, 2023· Updated Apr 1, 2025
CVE-2023-24057
CVE-2023-24057
Description
HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via directory traversal from a crafted ZIP or TGZ archive (for a prepackaged terminology cache, NPM package, or comparison archive).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ca.uhn.hapi.fhir:org.hl7.fhir.coreMaven | < 5.6.92 | 5.6.92 |
ca.uhn.hapi.fhir:org.hl7.fhir.convertorsMaven | < 5.6.92 | 5.6.92 |
ca.uhn.hapi.fhir:org.hl7.fhir.r4bMaven | < 5.6.92 | 5.6.92 |
ca.uhn.hapi.fhir:org.hl7.fhir.r5Maven | < 5.6.92 | 5.6.92 |
ca.uhn.hapi.fhir:org.hl7.fhir.utilitiesMaven | < 5.6.92 | 5.6.92 |
ca.uhn.hapi.fhir:org.hl7.fhir.validationMaven | < 5.6.92 | 5.6.92 |
Affected products
7- HL7/FHIR Core Librariesdescription
- ghsa-coords6 versionspkg:maven/ca.uhn.hapi.fhir/org.hl7.fhir.convertorspkg:maven/ca.uhn.hapi.fhir/org.hl7.fhir.corepkg:maven/ca.uhn.hapi.fhir/org.hl7.fhir.r4bpkg:maven/ca.uhn.hapi.fhir/org.hl7.fhir.r5pkg:maven/ca.uhn.hapi.fhir/org.hl7.fhir.utilitiespkg:maven/ca.uhn.hapi.fhir/org.hl7.fhir.validation
< 5.6.92+ 5 more
- (no CPE)range: < 5.6.92
- (no CPE)range: < 5.6.92
- (no CPE)range: < 5.6.92
- (no CPE)range: < 5.6.92
- (no CPE)range: < 5.6.92
- (no CPE)range: < 5.6.92
Patches
Vulnerability mechanics
Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
5- github.com/advisories/GHSA-jqh6-9574-5x22ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-24057ghsaADVISORY
- github.com/HL7/fhir-ig-publisher/security/advisories/GHSA-xr8x-pxm6-prjgghsaWEB
- github.com/hapifhir/org.hl7.fhir.core/commit/b50aec59124416b7315a49220cfc3999223414ccghsaWEB
- github.com/hapifhir/org.hl7.fhir.core/security/advisories/GHSA-jqh6-9574-5x22ghsaWEB
News mentions
0No linked articles in our index yet.