CVE-2023-24057: Path Traversal
HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via directory traversal from a crafted ZIP or TGZ archive (for a prepackaged terminology cache, NPM package, or comparison archive).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-24057?
CVE-2023-24057 is considered a moderate severity vulnerability due to its potential impact on data extraction and integrity.
How do I fix CVE-2023-24057?
To fix CVE-2023-24057, upgrade the HL7 FHIR Core Libraries to version 5.6.92 or later.
What types of attacks are possible with CVE-2023-24057?
CVE-2023-24057 allows attackers to perform directory traversal attacks to extract files into arbitrary directories.
Which software versions are affected by CVE-2023-24057?
CVE-2023-24057 affects HL7 FHIR Core Libraries before version 5.6.92 and HL7 FHIR IG Publisher before version 1.2.30.
Is CVE-2023-24057 exploitable in production environments?
Yes, CVE-2023-24057 is exploitable in production environments where vulnerable software is being used.