High severity7.5NVD Advisory· Published Dec 12, 2023· Updated Jun 17, 2026
CVE-2023-28465
CVE-2023-28465
Description
The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to certain directories via directory traversal, if an allowed directory name is a substring of the directory name chosen by the attacker. NOTE: this issue exists because of an incomplete fix for CVE-2023-24057.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ca.uhn.hapi.fhir:org.hl7.fhir.coreMaven | < 5.6.106 | 5.6.106 |
ca.uhn.hapi.fhir:org.hl7.fhir.convertorsMaven | < 5.6.106 | 5.6.106 |
ca.uhn.hapi.fhir:org.hl7.fhir.r4bMaven | < 5.6.106 | 5.6.106 |
ca.uhn.hapi.fhir:org.hl7.fhir.r5Maven | < 5.6.106 | 5.6.106 |
ca.uhn.hapi.fhir:org.hl7.fhir.utilitiesMaven | < 5.6.106 | 5.6.106 |
ca.uhn.hapi.fhir:org.hl7.fhir.validationMaven | < 5.6.106 | 5.6.106 |
Affected products
6- ghsa-coords6 versionspkg:maven/ca.uhn.hapi.fhir/org.hl7.fhir.convertorspkg:maven/ca.uhn.hapi.fhir/org.hl7.fhir.corepkg:maven/ca.uhn.hapi.fhir/org.hl7.fhir.r4bpkg:maven/ca.uhn.hapi.fhir/org.hl7.fhir.r5pkg:maven/ca.uhn.hapi.fhir/org.hl7.fhir.utilitiespkg:maven/ca.uhn.hapi.fhir/org.hl7.fhir.validation
< 5.6.106+ 5 more
- (no CPE)range: < 5.6.106
- (no CPE)range: < 5.6.106
- (no CPE)range: < 5.6.106
- (no CPE)range: < 5.6.106
- (no CPE)range: < 5.6.106
- (no CPE)range: < 5.6.106
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-9654-pr4f-gh6mnvdThird Party AdvisoryADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-28465ghsaADVISORY
- github.com/hapifhir/org.hl7.fhir.core/blob/b0daf666725fa14476d147522155af1e81922aac/org.hl7.fhir.r4b/src/main/java/org/hl7/fhir/r4b/terminologies/TerminologyCacheManager.javaghsaWEB
- github.com/hapifhir/org.hl7.fhir.core/pull/1162ghsaWEB
- github.com/hapifhir/org.hl7.fhir.core/releases/tag/5.6.106ghsaWEB
- github.com/hapifhir/org.hl7.fhir.core/security/advisories/GHSA-9654-pr4f-gh6mghsaWEB
- www.smilecdr.com/our-blognvdNot ApplicableWEB
- www.smilecdr.com/our-blog/statement-on-cve-2023-24057-smile-digital-healthnvdBroken LinkWEB
News mentions
0No linked articles in our index yet.