CVE-2014-3862: Infoleak
Published Sep 2, 2014
·Updated
CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to discover potentially sensitive URLs via a crafted reference element that triggers creation of an IMG element with an arbitrary URL in its SRC attribute, leading to information disclosure in a Referer log.
Affected Software
1 affected component
HL7 C-CDA<=1.1
Remediation
Event History
Sep 2, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3862?
CVE-2014-3862 is considered a medium severity vulnerability due to information disclosure risks.
2
How do I fix CVE-2014-3862?
To mitigate CVE-2014-3862, update to a version of HL7 C-CDA that is later than 1.1.
3
What types of systems are affected by CVE-2014-3862?
CVE-2014-3862 affects systems using HL7 C-CDA versions 1.1 and earlier.
4
What is the impact of CVE-2014-3862?
The impact of CVE-2014-3862 can lead to potential exposure of sensitive URLs in Referer logs.
5
Who can exploit CVE-2014-3862?
Remote attackers can exploit CVE-2014-3862 through crafted reference elements.