The HL7 FHIR IG publisher is a tool to take a set of inputs and create a standard FHIR IG. Prior to version 1.7.4, XSLT transforms performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag ( ]> could produce XML containing data from the host system. This impacts use cases where org.hl7.fhir.publisher is being used to within a host where external clients can submit XML. A previous release provided an incomplete solution revealed by new testing. This issue has been patched as of version 1.7.4. No known workarounds are available.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/52xxx/CVE-2024-52807.json",
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-611"
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-52807.json"
"2026-07-22T03:35:46Z"
[
{
"target": {
"file": "org.hl7.fhir.publisher.core/src/main/java/org/hl7/fhir/igtools/publisher/utils/PackageReleaser.java",
"function": "loadXml"
},
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2024-52807-4bc27bd2",
"signature_version": "v1",
"source": "https://github.com/hl7/fhir-ig-publisher/commit/3560de2f486d688a3ddcf4aa54d8bdacea380c3d",
"digest": {
"function_hash": "125032623781962091742545938696286363395",
"length": 188.0
}
},
{
"target": {
"file": "org.hl7.fhir.publisher.core/src/main/java/org/hl7/fhir/igtools/publisher/utils/TemplateReleaser.java",
"function": "loadXml"
},
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2024-52807-6da42913",
"signature_version": "v1",
"source": "https://github.com/hl7/fhir-ig-publisher/commit/3560de2f486d688a3ddcf4aa54d8bdacea380c3d",
"digest": {
"function_hash": "125032623781962091742545938696286363395",
"length": 188.0
}
},
{
"target": {
"file": "org.hl7.fhir.publisher.core/src/main/java/org/hl7/fhir/igtools/publisher/Publisher.java"
},
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2024-52807-7d3f6ec2",
"signature_version": "v1",
"source": "https://github.com/hl7/fhir-ig-publisher/commit/3560de2f486d688a3ddcf4aa54d8bdacea380c3d",
"digest": {
"line_hashes": [
"286811880020005909165061412211653982086",
"299970608237279827010939225668209095820",
"311620975348315132218038780777706646608",
"41675738926230356564796591267357126765"
],
"threshold": 0.9
}
},
{
"target": {
"file": "org.hl7.fhir.publisher.core/src/main/java/org/hl7/fhir/igtools/publisher/utils/TemplateReleaser.java"
},
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2024-52807-9c32237a",
"signature_version": "v1",
"source": "https://github.com/hl7/fhir-ig-publisher/commit/3560de2f486d688a3ddcf4aa54d8bdacea380c3d",
"digest": {
"line_hashes": [
"110532907982535572360180372312618593215",
"79848413141196994342160899263133626313",
"122697087731619263018250042838010918393",
"20236015585488005513050915663528874657"
],
"threshold": 0.9
}
},
{
"target": {
"file": "org.hl7.fhir.publisher.core/src/main/java/org/hl7/fhir/igtools/publisher/utils/PackageReleaser.java"
},
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2024-52807-a69e1b87",
"signature_version": "v1",
"source": "https://github.com/hl7/fhir-ig-publisher/commit/3560de2f486d688a3ddcf4aa54d8bdacea380c3d",
"digest": {
"line_hashes": [
"110532907982535572360180372312618593215",
"79848413141196994342160899263133626313",
"122697087731619263018250042838010918393",
"20236015585488005513050915663528874657"
],
"threshold": 0.9
}
},
{
"target": {
"file": "org.hl7.fhir.publisher.core/src/main/java/org/hl7/fhir/igtools/publisher/Publisher.java",
"function": "loadMappingSpaces"
},
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2024-52807-ea351fd1",
"signature_version": "v1",
"source": "https://github.com/hl7/fhir-ig-publisher/commit/3560de2f486d688a3ddcf4aa54d8bdacea380c3d",
"digest": {
"function_hash": "244466554406428647838315517336578751678",
"length": 1157.0
}
}
]