CVE-2025-24363

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-24363
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-24363.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-24363
Aliases
Published
2025-01-24T18:54:44Z
Modified
2025-11-13T19:52:25.763602Z
Severity
  • 4.2 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
The HL7 FHIR IG publisher may potentially expose GitHub repo user and credential information
Details

The HL7 FHIR IG publisher is a tool to take a set of inputs and create a standard FHIR IG. Prior to version 1.8.9, in CI contexts, the IG Publisher CLI uses git commands to determine the URL of the originating repo. If the repo was cloned, or otherwise set to use a repo that uses a username and credential based URL, the entire URL will be included in the built Implementation Guide, exposing username and credential. This does not impact users that clone public repos without credentials, such as those using the auto-ig-build continuous integration infrastructure. This problem has been patched in release 1.8.9. Some workarounds are available. Users should ensure the IG repo they are publishing does not have username or credentials included in the origin URL. Running the command git remote origin url should return a URL that contains no username, password, or token; or users should run the IG Publisher CLI with the -repo parameter and specify a URL that contains no username, password, or token.

Database specific
{
    "cwe_ids": [
        "CWE-200"
    ]
}
References

Affected packages

Git / github.com/hl7/fhir-ig-publisher

Affected ranges

Type
GIT
Repo
https://github.com/hl7/fhir-ig-publisher
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.1.0
1.1.1
1.1.10
1.1.100
1.1.101
1.1.102
1.1.103
1.1.104
1.1.105
1.1.106
1.1.107
1.1.108
1.1.109
1.1.11
1.1.110
1.1.111
1.1.112
1.1.113
1.1.114
1.1.115
1.1.116
1.1.117
1.1.118
1.1.119
1.1.12
1.1.120
1.1.121
1.1.122
1.1.123
1.1.124
1.1.125
1.1.126
1.1.127
1.1.128
1.1.129
1.1.13
1.1.130
1.1.131
1.1.14
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.2
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
1.1.25
1.1.26
1.1.27
1.1.3
1.1.32
1.1.33
1.1.34
1.1.35
1.1.37
1.1.38
1.1.39
1.1.4
1.1.40
1.1.41
1.1.42
1.1.43
1.1.44
1.1.45
1.1.47
1.1.48
1.1.5
1.1.50
1.1.51
1.1.53
1.1.54
1.1.55
1.1.56
1.1.57
1.1.58
1.1.59
1.1.6
1.1.60
1.1.61
1.1.62
1.1.63
1.1.64
1.1.65
1.1.66
1.1.67
1.1.68
1.1.7
1.1.71
1.1.72
1.1.73
1.1.74
1.1.75
1.1.76
1.1.77
1.1.78
1.1.79
1.1.8
1.1.80
1.1.81
1.1.82
1.1.83
1.1.84
1.1.85
1.1.86
1.1.87
1.1.88
1.1.89
1.1.9
1.1.90
1.1.91
1.1.92
1.1.93
1.1.94
1.1.95
1.1.96
1.1.97
1.1.98
1.1.99
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.22
1.2.23
1.2.24
1.2.25
1.2.26
1.2.27
1.2.28
1.2.29
1.2.3
1.2.30
1.2.31
1.2.32
1.2.33
1.2.34
1.2.35
1.2.36
1.2.37
1.2.38
1.2.39
1.2.4
1.2.40
1.2.41
1.2.42
1.2.43
1.2.44
1.2.45
1.2.46
1.2.47
1.2.48
1.2.49
1.2.5
1.2.50
1.2.51
1.2.52
1.2.53
1.2.54
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.10
1.3.11
1.3.12
1.3.13
1.3.14
1.3.15
1.3.16
1.3.17
1.3.18
1.3.19
1.3.2
1.3.20
1.3.21
1.3.22
1.3.23
1.3.24
1.3.25
1.3.26
1.3.27
1.3.28
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.4.1
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.1
1.5.10
1.5.11
1.5.12
1.5.13
1.5.14
1.5.15
1.5.16
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.8
1.5.9
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.13
1.6.14
1.6.15
1.6.16
1.6.17
1.6.18
1.6.19
1.6.2
1.6.20
1.6.21
1.6.22
1.6.23
1.6.24
1.6.25
1.6.26
1.6.27
1.6.28
1.6.29
1.6.3
1.6.30
1.6.31
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.8.8