HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via directory traversal from a crafted ZIP or TGZ archive (for a prepackaged terminology cache, NPM package, or comparison archive).
{ "versions": [ { "introduced": "0" }, { "fixed": "5.6.92" } ] }
{ "versions": [ { "introduced": "0" }, { "fixed": "1.2.30" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-24057.json"