VYPR
High severity7.5NVD Advisory· Published Dec 12, 2023· Updated Jun 17, 2026

CVE-2023-28465

CVE-2023-28465

Description

The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to certain directories via directory traversal, if an allowed directory name is a substring of the directory name chosen by the attacker. NOTE: this issue exists because of an incomplete fix for CVE-2023-24057.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
ca.uhn.hapi.fhir:org.hl7.fhir.coreMaven
< 5.6.1065.6.106
ca.uhn.hapi.fhir:org.hl7.fhir.convertorsMaven
< 5.6.1065.6.106
ca.uhn.hapi.fhir:org.hl7.fhir.r4bMaven
< 5.6.1065.6.106
ca.uhn.hapi.fhir:org.hl7.fhir.r5Maven
< 5.6.1065.6.106
ca.uhn.hapi.fhir:org.hl7.fhir.utilitiesMaven
< 5.6.1065.6.106
ca.uhn.hapi.fhir:org.hl7.fhir.validationMaven
< 5.6.1065.6.106

Affected products

6

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.